I know this especially well because I automatically clear all browsing data each time I close my browser, and techcrunch.com is one of the domains I avoid on HN because of the more annoying "welcome" on any page. (edit: +n)
I know this especially well because I automatically clear all browsing data each time I close my browser, and techcrunch.com is one of the domains I avoid on HN because of the more annoying "welcome" on any page. (edit: +n)
And then, in the end, you undo all your hard work opting out of hundreds of services by having to press the accept button anyway. :-D
/edit: Heh, yea. It’s not just “hundreds”. It is _way more than 1000_ “partners”. Insane.
There's no reason we can't have sites set an auth token, and send that in under the Authorization header. And then when you want to sign out of a website, you can have a button for that in the browser. The tooling already exists in the HTTP standard, it's just that it's only widely used for server-server communication.
I don't see much of a solution other than making it a matter of policy, eg. Microsoft's "P3P" header. Otherwise authentication credentials need to be supplied with every request. Not a session id or token as a cookie, but the actual username and password being supplied with every request. Basically the old http basic auth, but with a more modern system to replace it.
I understand the core idea behind the EU's desire, but the fact is that cookies are absolutely required for login sessions, and it's impossible to allow users to opt out. The EU doesn't understand the tech behind the laws they are trying to enforce, and this is where it leads to. Absurdity.
GDPR is absolutely not about cookies, it's not about having private information but about uses of it. You may have a legitimate need to collect some data - that auth token for login purposes, the customer's address for delivery, etc. That's fine, it allows you to collect and use that data for that purpose. But it does not mean that you're automatically allowed to use that login token or delivery address you have on your servers for other purposes such as selling or giving it to third party advertisers.
- A/B testing.
- Limiting the number of articles a non-paying user can read per month.
- Persisting form data and shopping cart info. (Not all sites require an account to order stuff from them.)
- Improving recommendations based on what someone has liked or viewed on the site.
It doesn't realise I'm on firefox, so doesn't preferentially serve me a primary focus?
Though you'll need an additional extension to auto-accept.
Plant all the cookies you like, they'll last about 3 minutes.
The bookmarklet:
javascript:(function()%7B(function%20()%20%7Bvar%20i%2C%20elements%20%3D%20document.querySelectorAll('body%20*')%3Bfor%20(i%20%3D%200%3B%20i%20%3C%20elements.length%3B%20i%2B%2B)%20%7Bif%20(getComputedStyle(elements%5Bi%5D).position%20%3D%3D%3D%20'fixed')%20%7Belements%5Bi%5D.parentNode.removeChild(elements%5Bi%5D)%3B%7D%7D%7D)()%7D)()It's breaking the layout of this entire comment thread for me so I have to scroll horizontally to read all of the comments. Thanks!
``` javascript:(function () { var i, elements = document.querySelectorAll('body *'); var style;
document.body.style.overflow-y = 'auto'
for (i = 0; i < elements.length; i++) {
style = getComputedStyle(elements[i]);
if (style.position === 'fixed' && style.top !== "0px") {
elements[i].style.display = 'none';
}
}
})()
```https://gdpr-info.eu/recitals/no-32/
There's a lot of detail, but the most important part is this: "...inactivity should not therefore constitute consent."
While I'm not sure there's an EU-wide ruling, the Greek DPA has specifically called out the "Consent" option being more visually prominent than the "Not Consent" option. They also mention the anti-pattern of bugging for consent daily but not bugging for un-consent afterwards, but that probably runs more afoul of "consent must be as easy to withdraw as to give" rather than "freely given."
If a site wants to use data in ways that need consent (by the way, most reasonable uses don't need consent because 'legitimate need' applies - it's pretty much only things like "use all your private data for targeted advertising" and "share your private data with these 1000 trusted partners" that need consent) then it's the burden of the site to ensure that the options are presented in a clear, nonconfusing way, that users get fully informed, etc, and demonstrate to the data protection agency that whatever they implemented achieves these goals.
"Just highlighting the ‘no consent button’ after a massive set of options" most likely is not effective to that goal, and a data protection agency can easily verify that (run a study with 10 new users signing up for the site and fill out a questionairre of what they wanted to consent) so it should invite administrative action from the DPAs, with mandates to change the system and/or fines depending on the circumstances. It's just that they're not really bothering with random websites (yet?) since the majority of their work is on how the all the EU non-web businesses (e.g. retailer loyalty programs, phone providers, banks, etc) handle private data.
How is this even possible without setting up a video meeting where a consent officer interviews you and quizzes you to make sure you understood your rights and what you were consenting to?
This seems like an exceedingly onerous thing to demonstrate
The EU does not act like the US - if there's a piece of law, there is guidance on how to comply with that law. You follow it and you're safe, until someone publishes updated guidance.
A number of companies are betting that doing something short of what the guidance recommends will still result in a compliant website. They are in a situation where, if they attract the attention of a regulating body, they may be fined.
And what if your cat walks across the keyboard and accidentally consents, but you never even realized it? Should there be a consent banner across the top at all times? Or what if you are drunk when you are surfing the web and didn't understand your rights when you accidentally consented (drunk people can't consent - the website raped your privacy)?
Person: "I swear I didn't consent! I didn't even see the dialogue! My cat must've walked across the keyboard and accidentally consented"
Ok, you're the judge, what's your call?
Should the dialogue force you to have to type: "I've read and consent to the terms ..." ?
If the company refuse, or if the user claims he was tricked into agreeing, then there is cause for further investigation.
And it's not going to be a judge from the start, but whatever organism is charged with compliance. Then, if they have a case, a judge gets involved.
But this discussion is full of examples of "consent" dialogues that clearly are made to trick users into making a different choice than what they want. In such cases showing the logs and dialogues would demonstrate that a valid consent was not obtained.
It's not a novel thing - for example, I recall that many years ago website opt-in patterns were being reviewed in the Ryanair case where the consumer rights agencies analyzed their website order process where a bunch of 'dark patterns' were used so that people accidentally "opting in" to things they did not want to. There's an administrative process that determines whether your process is honest or tries to cheat users into "agreeing" to things they don't intend to agree. In the latter case, you'll be forced to change how your stuff works.
i am sure there are many databases out there which i am marked as having consented it, although i did no such thing. the standard is to make it hard to express your desire to opt out despite the rules requiring entirely the opposite.
E.g. at the launch of GDPR a local major supermarket chain tried to use a bunch of dark patterns for their loyalty card program (mostly offline) process so as to continue their tracking, they were forced to change last year. It's clear that issues like that have a much larger impact on privacy of people than some foreign news website, and that's prioritized accordingly.
For the major multinational social networks, the delays are (intentionally?) caused by the lack of capacity in the Ireland data protection agency, as many of these multinationals have their EU HQ in Ireland because of tax purposes, so all their cases are being handled there and that means that enforcement for them is going to take a long time. But if I look at random local websites today and compare it to what was happening a year ago, the dark patterns are not prevalent anymore. They appear occasionally, but they're really rare now locally.
I assume they hope you just click agree instead.
And if it doesn't, I leave.
If I was a European citizen, then I believe by default I did not allow anything. They would be in abeyance of the GDPR if they were to track or identify me.
If I can jam up even a bit of tracking with a PiHole, ublock origin, privacy badger, Bypass Paywalls Clean, Containers, and more, good on me. Im already inexorably tied to google at the moment, and working to remove myself from their ties.
Also, they're probably breaking the law.
A better solution is websites actually accepting the “do not track” requests that browsers already send. Unfortunately the most popular web browser is run by the most popular tracking company, who also almost wholly funds the second most popular browser.
It costs money and gives them nothing in return
Also, Ad Blockers are becoming quite prevalent again. Personally, I’ve started using one again for privacy reasons. If a publisher would actually respect my Do Not Track request, I’d happily leave their ads up. I have no problem with contextual advertising.
So that’s revenue left on the table.
I have a website. If I wanted to support DNT, I'd have to take an hour or two to figure it out. To be honest, it wasn't even on my radar.
Techcrunch routinely ends up on the front page on HN, ironically many times for articles that condemn the very practices they engage in. No website will change their practices because of strong, informed opinions when the clicks still come in, especially from a distinguished community like HN that just validates Techcrunch's choices.
So maybe it'll be fax instead of email. Or a weekly letter with a list of all the IPs that have revoked consent? I'm pretty sure this could be done very cost effectively if it's many users and only a small pool of bad UI offenders.
The problem is: how do you get everyone to cooperate at the same time when the incentive for cheating is that your website gets all the revenue?
This dilemma is just one of many in modern society and all are aspects of Moloch [1]. Ultimately we’d like to kill Moloch but that seems very difficult right now.
[1] https://slatestarcodex.com/2014/07/30/meditations-on-moloch/
By cutting to the source and making targeted internet advertisements illegal, full stop, with business-wrecking, revenue-scaled fines implemented for both offending websites and offending ad companies.
An effective ad on a popular website could be a single jpg hosted on the same webserver as that website itself. You wouldn't need any Cookie banner for that.
But ohh, that isn't enough. No they want to be able to show your users content you didn't explicitly approve and run code on your users computers you cannot verify.
If you had a lemonade stand would you let some company film your customers faces? Probably not.
The GDPR law just makes sure you ask them before you do it
Anyway, I boycott TC since they started their war on users.
Prequel, website owners, android developers,... PLEASE, please, check this video. You will more or less understand everything you need to know about GDPR.
GDPR event London 2017 - with Tim Walters: https://www.youtube.com/watch?v=-stjktAu-7k
I think that someone is earning large bucks to trick different websites into believing that they can avoid GDPR by simple tricks while on the other side owners are just too lazy to read simple interpretations made by Article 29 Data Protection Working Party (no, it does not matter what your lawyer thinks if it contradicts recitals). I would call it a scam but I think that some enlightment must be pushed in place:
https://ec.europa.eu/newsroom/just/document.cfm?doc_id=48849
(page 16):
"Without prejudice to existing (national) contract law, consent can be obtained through a recorded oral statement, although due note must be taken of the information available to the data subject, prior to the indication of consent. The use of pre-ticked opt-in boxes is invalid under the GDPR. Silence or inactivity on the part of the data subject, as well as merely proceeding with a service cannot be regarded as an active indication of choice."
(page 21):
"Article 7(3) of the GDPR prescribes that the controller must ensure that consent can be withdrawn by the data subject as easy as giving consent and at any given time. The GDPR does not say that giving and withdrawing consent must always be done through the same action. However, when consent is obtained via electronic means through only one mouse-click, swipe, or keystroke, data subjects must, in practice, be able to withdraw that consent equally as easily."
and then never shows it again, so i don't really know where i would go to manage consent.
i don't see why companies can't just behave like decent human beings. why do they want me to not trust them?
First you see the warning banner that has the large prominent "CONTINUE (i consent)" CTA button with a tiny "options" link somewhere below.
If you catch that "options" is code for "I don't want to consent", you're then brought to a wall of legalize that you need to scroll to the bottom to find the double-negative-ambiguous-toggle labelled "Do not sell my privacy data". So you need to enable it to disable tracking. I think. But even so, it's a toggle UI instead of a checkbox, so you're not quite sure what state means what.
There's one particular provider of these consent forms out there that a lot of sites use... I'm sure their marketing materials say "our world-class designers have identified the best and most clear user-design principles, which we have inverted to minimize your opt-out conversion rate!"
I wonder where things are heading.
If there is such a company I'm completely ok with them not being viable anymore.
i don't know where all the misinformation comes from, but companies don't need to provide their services for free. they can still show ads - just untargeted ones. or is ads = tracking nowadays?
This is what Google's advertising product started out as, basically automated magazine advertising at scale; it turned into this perverse tracking system once everyone was hooked onto free web content and nobody could get away from it.
Or you can just leave the website. It's not like you lose anything by not going to techcrunch, let alone lose your job or anything serious.
Targeted ads make the website a lot more money.
Your original statement made it sound as if you were saying all regulation is justified. Thanks for the primer on free-market/regulatory trade-offs though I never realized there was room for nuance.
The idea of GDPR generally is to prevent some undesirable behaviour (i.e. indiscriminately vacuuming up all the personal data you can and being careless with it), in part by establishing a regulation that says "you need to have good reasons if you want to process personal data". This means we have to define, among other things, what "good reasons" are.
In GDPR terms this would be the "lawful basis" for processing data. There are a bunch of these, including "you gave explicit consent", "it is a legal requirement", and "we have a legitimate interest in doing so".
The thing is, if "consent" is the basis on which you are processing data, then you cannot reasonably refuse service to someone who witholds consent – because that action would itself demonstrate that consent is not the lawful basis you are using. It's not a ban on discrimination, but the fact that your argument for why you need to process personal data would no longer be valid.
This seems backward to me - by allowing access to users who don't consent, you are implying that consent to track is not at all necessary to your functioning, and thus doing the tracking at all is now for invalid reasons... yea?
Think of it like this - if you want to process some personal data, regulations now oblige you to have a justification for doing so. That’s what GDPR calls a “lawful basis”, and there are six of them that can be used:
- Contract – "processing your data is required to offer or fulfil a contract with you"
- Consent – "we asked to process your data and you explicitly said it was okay"
- Legal obligation – "we need to process your data to comply with the law"
- Vital interest – "you were likely to die unless we processed this data"
- Public task – "we need to process your data to perform some kind of officially sanctioned public service"
- Legitimate interest – "we need to process this data for some other legitimate reason and promise that we won't do anything unexpected or unreasonable with it"
So, if you're running a website and you want to collect visitor data, you now need to justify why you are doing so, using one of these reasons. Each of these reasons outlines when they can be used, and what conditions apply to their use as a justification.
If you were running e.g. an insurance comparison site, you'd use the "contract" basis – processing a subject's data is necessary to fulfil some kind of service. A separate "consent" is not required. If you wanted to log requests to your site so you can detect intrusion attempts, you have a "legitimate interest" basis and again "consent" is not required – instead, you need to ensure you have evaluated the data you collect and demonstrated why it is required to fulfil that function.
To the specific point you raised – if your website legitimately needs to process data for reasons that are "necessary to your functioning", then you do not need consent to do so. You do need to document why this is the case, communicate it to users, provide adequate safeguards etc. but don't need to obtain an explicit consent. If you aren't able to use this approach, you still need a justification for your processing; if you want to use "explicit consent" as your reason, then that comes with the requirement that the consent is freely-given, explicitly opt-in, and is not a precondition for accessing the service.
If you decided to make "consent" a requirement to access a service, you would inherently be demonstrating that you did not meet the requirements for making that your "lawful basis" for processing.
Sorry that came out quite long, but I think it's important that anybody working with personal data understands these ideas!
Thanks!
Even sexual orientation isn't really protected in that way FWIW, which is why a lot of anti-discrimination rulings surrounding LGBT rights can often feel a bit convoluted.
Edit: I'm surprised that elondaits's explanation isn't at the top of my thread. It makes clear that "exchanging your data as payment for 'free' services" is the target of GDPR and seems to me that's the only sensible explanation. Is someone willing to refute their explanation?
In this case, however, I was using it as an example of setting a price you don't expect to be paid... you want everyone to pay with their data, but you are required by law to offer an alternative payment form... so you set the price for the alternative to so high no one pays it.
It probably wouldn't surprise you that it is unlawful to require visitors to sacrifice a kitten to access a site, would it?
I understand that the GDPR makes it illegal to make it necessary to consent to give up your data before gaining entry. I was just questioning that portion of the law. It would be a pointless conversation to question points of a law and have someone respond back "but that is the law".
Actually, in some countries, outside narrow restricted cases like support groups, yes; criminal record is a protected class in some cases.
However, being an ex-con isn't illegal. Having a club where you required members to consent to a crime being committed against them, which is more analogous here, wouldn't be legal.
But this thing where big sites say "data or else" isn't a proper negotiation. It's a contract of adhesion, and those get regulated for good reason.
If things get moved behind expensive paywalls, that's a shame. But if there is more truely free access, or content behind paywalls that charge as much as an ad is worth, that can be a net benefit.
That's only true under ideological assumptions that are far from universal. I think most people would be OK with society putting reasonably-justified restrictions on the kinds of rules the club can set.
The point of the law is quite clear: allowing people to use the web without having anyone force them into giving away personal information.
Sure, some companies won't be able to be creepy to users, but that was an acceptable tradeoff to the law.
I just don't see people really caring about their privacy. When given the choice between convenience and privacy people generally choose convenience. As someone who doesn't have a dog in this fight, I just end up annoyed.
And just because people don't care doesn't mean a company is automatically allowed to track people.
If the law were followed by the letter and companies weren't using dark patterns or ambiguous marketing-speak to convince people to allow cookies, only people with pro-tracking stances would allow it.
I assume it would be legal to charge money for reading the content... could they require that you create an account?
It does seem to lead to some strange loopholes though, like requiring an account for access.
That's false.
Requiring an account or even payment for access does not replace or imply consent of any kind, and all rules still apply even if the user is still logged in or paying.
In fact, it's probably more complicated for logged-in users since you have to comply to requirements of data-scrubbing, removing/anonymising logins/emails/passwords from your database upon request, etc.
Meaning: more code that you have to write and time you have to spend.
I've found that sites are slowly changing over to this method but it will probably take a big court case for the likes of TechCrunch to change.
Edit: Never mind, I guess that would violate Article 7's "It shall be as easy to withdraw as to give consent."
Wait--that exists? Then Oath _definitely_ is violating GDPR. Continuing without consent is basically impossible on their websites!
Companies like Verizon can get away with this abuse because we're all too lazy to report them in an instant.
Verizon has offices in the United Kingdom, Ireland, Belgium and the Czech Republic, but you can also use the online form of your country to report them in the EU.
File a complaint against Verizon and TechCrunch here:
UK: https://ico.org.uk/make-a-complaint/your-personal-informatio...
Ireland: https://www.dataprotection.ie/en/individuals/raising-concern...
However, EU GDPR legislation permits the EU to do whatever it can go after noncompliant sites in any jurisdiction. The legislation also requires all new trade agreements between the EU and other countries to be GDPR-compliant. The legislation permits them to go after "noncompliant" sites for 4% of worldwide revenue. So it's quite brutally extraterritorial by design.
The interpretation of the regulation does not require large fines for small infractions by non-EU-focused sites, and indeed the regulators presently work to be eminently reasonable about such things, but the lines are fuzzy and the interpretation could change without further legislation — and even if you could defend yourself against such a case, it may be ruinous anyway.
But if the company has no offices, bank accounts or other business presence in the EU, there is no practical way to enforce it.
So, if sites can't provide users with anything in return for consenting, doesn't that make consenting not a valid contract? Or does the EU not require a contract to have an exchange of value?
So can they do previews only without running afoul of the law and they specifying cookies for full access?
Consent that's not freely given is not valid legal basis for processing personal data according to GDPR. If users clicked "I agree" under these circumstances, then that "agreement" click is worthless, it does not grant any extra permission that the website owner did not already have.
In essence, GDPR makes that consent to processing private data is not for sale, it's not something you can legally trade away in a contract for some money or benefit.
It's valid to have informative click-through walls - to gather assertions that the user has been informed that you're going to do stuff with their data because you have a legal basis to do it even if they don't opt-in; but a click-through wall fundamentally can not be a mechanism of obtaining valid consent to some processing where consent is needed. GDPR consent must be opt-in, fully informed, and freely given - something that some of your users intentionally choose because they want to. If you expect all users to "consent" to some processing then that's impossible - you would rather have to argue that the "legitimate need" or some other part of GDPR allows you to process that data without consent. You can have all users acknowledge something, but you can't have all users consent to something, that's not how opt-in consent works.
Several Austrian and German Newspapers present me with a clear popup choice "Accept Tracking" or "Pay Money"
The Washington post does the same.
Websites are not required to give you their content for free.
But websites are not allowed to track people who don't really want to be tracked. If the choice was "accept tracking or go away" then clicking "accept tracking" does not give them a legally valid consent to track me. There's nothing illegal about that popup as such, it's the tracking without consent that would be a violation.
Can you give me a link to some of these Austrian and German newspapers so that I can try out their approval pipeline? If that's really the case (all kinds of minor nuances may change the situation) then my intent is to click "accept", followed by a GDPR request of how they're using my data, and if their response indicates "consent" as the basis for processing something, then I'll submit a complaint to my local DPA (which may get resolved by the end of year..)
My point is that some EU companies still doing X is not a sign that X is permitted - often all it means that GDPR is not enforced for them yet. I see a lot of local practices that are still happening despite our local DPA clearly stating that this is not 'kosher' - it takes a lot of time to make all industries comply, there have been a lot of changes (mostly for the mass market companies handling offline customers, everything from hospitals to the rental markets to supermarket loyalty cards) but there's a lot of noncompliance out there. Every now and then another subindustry gets investigated (probably prioritized by the number of complaints) and after some action gets taken, all the other local companies in that industry tidy up somewhat.
I'we only seen "Accept ads" or "Pay Money", which makes it bit different.
There are also non-tracking ads, and you can consent to be tracked even if you pay money.
Which is absurd. Did I not "freely give" $20 when I bought a pizza because if I had been able to get the pizza without paying I would have?
GDPR consent must be opt-in, fully informed, and freely given - something that some of your users intentionally choose because they want to.
And there's no reason for customers to opt-in when you're not allowed to offer anything in exchange. I would respect the GDPR a lot more if it directly banned "unnecessary" data collection, rather than going through these silly rituals of companies using dark patterns to try to claim that users agreed.
The valid reasons for customers to opt-in are in scenarios where they desire the result to be customised according to that private data - where the customer wants you to use that data because that actual use benefits them. E.g. a dating site user might want you to use all kinds of private data for the purposes of finding better date matches. And the same user might not want you to use that same data for any other purposes or share it with third parties. And the intended result of GDPR (as the enforcement slowly changes the common practices) is a world where these user's privacy preferences are actually respected.
So the consent question comes down to essentially "are the users gifting you this data because they want you to have it?" - if so, knock yourself out, everyone's happy. But any selling or trading that consent is not binding or enforceable.
The most effective analogy that I can think of is sexual consent.
Like, if I sign a contract saying "You can fuck my arse and I get 5 euros for that" then that by itself does not count as valid consent, that's a nonenforceable term, it's null and void. At every future point I'm free to not have my arse fucked unless I really want to (or there's some other legal basis, IDK, a warrant for a cavity search), that's an unalienable right, it's not something that I can sign away in a contract, and doing so without my actual consent would be rape no matter what I signed in the contract.
In the exact same manner, under GDPR if I sign a contract saying "You can violate my privacy and I get 5 euros for that" then that by itself does not count as valid consent, that's a nonenforceable term, it's null and void. At every future point I'm free to not have my privacy violated unless I want to (or there's some other legal basis), that's an unalienable right, it's not something that I can sign away in a contract, and doing so without my actual consent would be a privacy rights violation despite the contract.
That’s fine, isn’t it? They want money, I want information. If the information is worth it, I pay.
So it's up to you to decide if the information is worthy? After already seeing that information? And you promise you will forget that information after not liking it and not paying for it?
It's of course classic upfront payment. I realize this only works for larger articles. For news feeds a subscription would probably work better.
This will probably lead to market consolidation over time, but that's capitalism.
Heck, what if they said that everyone doing things their way is their condition on staying in WIPO, and if a country can’t bring its corporations into line, then the EU will declare all WIPO IP-right assertions originating from that country null and void within the EU, free for any EU corporation to exploit?
EU would effectively be declaring war on a significant percentage of the world. They have no jurisdiction beyond their borders.
Taking your ball and going home, while not the best for business, should be an option.
Or, to put that another way: WIPO itself is something the US "forced" on the rest of the world. But it wasn't actually force; it was just a condition on other nations continuing to trade with the US.
As per wiktionary.org: "To cease participating in an activity that has turned to one's disadvantage, especially out of spite, or in a way that prevents others from participating as well."
You are assuming a point I did not make.
Lots of companies won't ship things to certain countries, that doesn't make it a trade war.
What the heck? That seems a bit overbearing.
It's my server. Don't agree to my rules? GTFO. Why should you have the right to ignore my rules and still use my server? That's like having your cake and eating it too.
"Thanks, I don't consent to your monetization scheme but I'll go ahead and use your bandwidth for free."
Remember that the law came only because web site owners took things way too far. Pendulums swing both ways.
It's not that they don't consent to your monetization scheme, is that a monetization scheme that involves tracking people who don't really want to be tracked is illegal as such, you can't have one. You can deny access to whoever you want, but the key point is that if you "threatened" them to deny service if they don't accept, then that does not really indicate that they wanted you to use their data, does it?
You can't say "oh but I gave them some goodies to influence them to click 'Accept'" - nope, if they don't really want to be tracked, then you aren't allowed to do so, the consent is not something that people can trade away in a contract for some content, server time, money, lentil soup or whatever.
I guess it depends wether you consider free plans to be a loss leader for the paid plans.
If you don't want to operate a free service that is without tracking, then don't. No-one is forcing you to, but you should be aware that you still need to follow the law for paying users too.
Or not. Personally I have no problem with cookies. Maybe they will just lose traffic from a small fraction of HN users instead of going out of business.
It’s kind of like paywalls. I get annoyed whenever I visit a news website and a paywall pops up, but I just leave the site unless I’m interested in subscribing. If enough people leave instead of paying (i.e. providing something of value in exchange for accessing interesting content), then the publication goes out of business.
Your point definitely makes a lot of sense, but there are many of us who believe that we should be able to make our own decision to give up certain types of privacy in exchange for something of value.
Everything involves some level of risk/reward. Should I not be allowed to skydive because of the increased risk of death? Generally, I think my rights end where others’ rights begin, so I fail to see how sharing or withholding my personal information affects anyone else.
So invading someone else's privacy, without their consent, for your own monetary gain, should be your decision, because it's fairer?
I didn’t say anything about not getting consent to share personal information. I think almost everyone would agree consent is always necessary.
This is what these laws are all about.
People volunteer personal information because they believe the website will use it with their best interests in mind. There is a well-defined goal and achieving it is the only reason the website even has access to such data. For example, people give their home address to an online store so they can ship orders. Selling this data to marketers so they can spam the consumer's mailbox with advertisements is outside the scope of that goal.
Websites should collect only what's strictly necessary for them to do whatever it is that they do. They should use this data only for this purpose and ideally delete it afterwards.
However, there are two reasons why I think this is still reasonable (with 1. being more important):
1. The reality of the current situation is that invasions of privacy come bundled with other services, which you are pressured to use due to external factors. So I believe that the vast majority of cases are modelled well.
2. I see a privacy as similar to herd immunity, in that society benefits if lots of people have it, even if the individual does not profit from it directly. (In particular, it may prevent certain kinds of power from accumulating or centralising.) In these kinds of situations it can be necessary to restrict individual rights to achieve optimality.
Sure. Just like I didn't click on the techcrunch link above, I'm sure I'll live without your server as well :)
It's european society. Don't agree to its rules? Don't try to monetize european citizens. Why should you have the right to ignore their rules and sell their personal information? That's like having your cake and eating it too.
One additional point should've been added to GDPR: malicious techniques to acquire consent will result in triple the amount of fines.