And then, in the end, you undo all your hard work opting out of hundreds of services by having to press the accept button anyway. :-D
/edit: Heh, yea. It’s not just “hundreds”. It is _way more than 1000_ “partners”. Insane.
And then, in the end, you undo all your hard work opting out of hundreds of services by having to press the accept button anyway. :-D
/edit: Heh, yea. It’s not just “hundreds”. It is _way more than 1000_ “partners”. Insane.
A better solution is websites actually accepting the “do not track” requests that browsers already send. Unfortunately the most popular web browser is run by the most popular tracking company, who also almost wholly funds the second most popular browser.
It costs money and gives them nothing in return
Also, Ad Blockers are becoming quite prevalent again. Personally, I’ve started using one again for privacy reasons. If a publisher would actually respect my Do Not Track request, I’d happily leave their ads up. I have no problem with contextual advertising.
So that’s revenue left on the table.
I have a website. If I wanted to support DNT, I'd have to take an hour or two to figure it out. To be honest, it wasn't even on my radar.
Techcrunch routinely ends up on the front page on HN, ironically many times for articles that condemn the very practices they engage in. No website will change their practices because of strong, informed opinions when the clicks still come in, especially from a distinguished community like HN that just validates Techcrunch's choices.
So maybe it'll be fax instead of email. Or a weekly letter with a list of all the IPs that have revoked consent? I'm pretty sure this could be done very cost effectively if it's many users and only a small pool of bad UI offenders.
The problem is: how do you get everyone to cooperate at the same time when the incentive for cheating is that your website gets all the revenue?
This dilemma is just one of many in modern society and all are aspects of Moloch [1]. Ultimately we’d like to kill Moloch but that seems very difficult right now.
[1] https://slatestarcodex.com/2014/07/30/meditations-on-moloch/
By cutting to the source and making targeted internet advertisements illegal, full stop, with business-wrecking, revenue-scaled fines implemented for both offending websites and offending ad companies.
An effective ad on a popular website could be a single jpg hosted on the same webserver as that website itself. You wouldn't need any Cookie banner for that.
But ohh, that isn't enough. No they want to be able to show your users content you didn't explicitly approve and run code on your users computers you cannot verify.
If you had a lemonade stand would you let some company film your customers faces? Probably not.
The GDPR law just makes sure you ask them before you do it
I assume they hope you just click agree instead.
There's no reason we can't have sites set an auth token, and send that in under the Authorization header. And then when you want to sign out of a website, you can have a button for that in the browser. The tooling already exists in the HTTP standard, it's just that it's only widely used for server-server communication.
I don't see much of a solution other than making it a matter of policy, eg. Microsoft's "P3P" header. Otherwise authentication credentials need to be supplied with every request. Not a session id or token as a cookie, but the actual username and password being supplied with every request. Basically the old http basic auth, but with a more modern system to replace it.
I understand the core idea behind the EU's desire, but the fact is that cookies are absolutely required for login sessions, and it's impossible to allow users to opt out. The EU doesn't understand the tech behind the laws they are trying to enforce, and this is where it leads to. Absurdity.
GDPR is absolutely not about cookies, it's not about having private information but about uses of it. You may have a legitimate need to collect some data - that auth token for login purposes, the customer's address for delivery, etc. That's fine, it allows you to collect and use that data for that purpose. But it does not mean that you're automatically allowed to use that login token or delivery address you have on your servers for other purposes such as selling or giving it to third party advertisers.
- A/B testing.
- Limiting the number of articles a non-paying user can read per month.
- Persisting form data and shopping cart info. (Not all sites require an account to order stuff from them.)
- Improving recommendations based on what someone has liked or viewed on the site.
It doesn't realise I'm on firefox, so doesn't preferentially serve me a primary focus?
Though you'll need an additional extension to auto-accept.
Plant all the cookies you like, they'll last about 3 minutes.
The bookmarklet:
javascript:(function()%7B(function%20()%20%7Bvar%20i%2C%20elements%20%3D%20document.querySelectorAll('body%20*')%3Bfor%20(i%20%3D%200%3B%20i%20%3C%20elements.length%3B%20i%2B%2B)%20%7Bif%20(getComputedStyle(elements%5Bi%5D).position%20%3D%3D%3D%20'fixed')%20%7Belements%5Bi%5D.parentNode.removeChild(elements%5Bi%5D)%3B%7D%7D%7D)()%7D)()It's breaking the layout of this entire comment thread for me so I have to scroll horizontally to read all of the comments. Thanks!
``` javascript:(function () { var i, elements = document.querySelectorAll('body *'); var style;
document.body.style.overflow-y = 'auto'
for (i = 0; i < elements.length; i++) {
style = getComputedStyle(elements[i]);
if (style.position === 'fixed' && style.top !== "0px") {
elements[i].style.display = 'none';
}
}
})()
```Anyway, I boycott TC since they started their war on users.
Prequel, website owners, android developers,... PLEASE, please, check this video. You will more or less understand everything you need to know about GDPR.
GDPR event London 2017 - with Tim Walters: https://www.youtube.com/watch?v=-stjktAu-7k
I think that someone is earning large bucks to trick different websites into believing that they can avoid GDPR by simple tricks while on the other side owners are just too lazy to read simple interpretations made by Article 29 Data Protection Working Party (no, it does not matter what your lawyer thinks if it contradicts recitals). I would call it a scam but I think that some enlightment must be pushed in place:
https://ec.europa.eu/newsroom/just/document.cfm?doc_id=48849
(page 16):
"Without prejudice to existing (national) contract law, consent can be obtained through a recorded oral statement, although due note must be taken of the information available to the data subject, prior to the indication of consent. The use of pre-ticked opt-in boxes is invalid under the GDPR. Silence or inactivity on the part of the data subject, as well as merely proceeding with a service cannot be regarded as an active indication of choice."
(page 21):
"Article 7(3) of the GDPR prescribes that the controller must ensure that consent can be withdrawn by the data subject as easy as giving consent and at any given time. The GDPR does not say that giving and withdrawing consent must always be done through the same action. However, when consent is obtained via electronic means through only one mouse-click, swipe, or keystroke, data subjects must, in practice, be able to withdraw that consent equally as easily."
and then never shows it again, so i don't really know where i would go to manage consent.
i don't see why companies can't just behave like decent human beings. why do they want me to not trust them?
And if it doesn't, I leave.
If I was a European citizen, then I believe by default I did not allow anything. They would be in abeyance of the GDPR if they were to track or identify me.
If I can jam up even a bit of tracking with a PiHole, ublock origin, privacy badger, Bypass Paywalls Clean, Containers, and more, good on me. Im already inexorably tied to google at the moment, and working to remove myself from their ties.
Also, they're probably breaking the law.
First you see the warning banner that has the large prominent "CONTINUE (i consent)" CTA button with a tiny "options" link somewhere below.
If you catch that "options" is code for "I don't want to consent", you're then brought to a wall of legalize that you need to scroll to the bottom to find the double-negative-ambiguous-toggle labelled "Do not sell my privacy data". So you need to enable it to disable tracking. I think. But even so, it's a toggle UI instead of a checkbox, so you're not quite sure what state means what.
There's one particular provider of these consent forms out there that a lot of sites use... I'm sure their marketing materials say "our world-class designers have identified the best and most clear user-design principles, which we have inverted to minimize your opt-out conversion rate!"
https://gdpr-info.eu/recitals/no-32/
There's a lot of detail, but the most important part is this: "...inactivity should not therefore constitute consent."
While I'm not sure there's an EU-wide ruling, the Greek DPA has specifically called out the "Consent" option being more visually prominent than the "Not Consent" option. They also mention the anti-pattern of bugging for consent daily but not bugging for un-consent afterwards, but that probably runs more afoul of "consent must be as easy to withdraw as to give" rather than "freely given."
If a site wants to use data in ways that need consent (by the way, most reasonable uses don't need consent because 'legitimate need' applies - it's pretty much only things like "use all your private data for targeted advertising" and "share your private data with these 1000 trusted partners" that need consent) then it's the burden of the site to ensure that the options are presented in a clear, nonconfusing way, that users get fully informed, etc, and demonstrate to the data protection agency that whatever they implemented achieves these goals.
"Just highlighting the ‘no consent button’ after a massive set of options" most likely is not effective to that goal, and a data protection agency can easily verify that (run a study with 10 new users signing up for the site and fill out a questionairre of what they wanted to consent) so it should invite administrative action from the DPAs, with mandates to change the system and/or fines depending on the circumstances. It's just that they're not really bothering with random websites (yet?) since the majority of their work is on how the all the EU non-web businesses (e.g. retailer loyalty programs, phone providers, banks, etc) handle private data.
How is this even possible without setting up a video meeting where a consent officer interviews you and quizzes you to make sure you understood your rights and what you were consenting to?
This seems like an exceedingly onerous thing to demonstrate
The EU does not act like the US - if there's a piece of law, there is guidance on how to comply with that law. You follow it and you're safe, until someone publishes updated guidance.
A number of companies are betting that doing something short of what the guidance recommends will still result in a compliant website. They are in a situation where, if they attract the attention of a regulating body, they may be fined.
And what if your cat walks across the keyboard and accidentally consents, but you never even realized it? Should there be a consent banner across the top at all times? Or what if you are drunk when you are surfing the web and didn't understand your rights when you accidentally consented (drunk people can't consent - the website raped your privacy)?
Person: "I swear I didn't consent! I didn't even see the dialogue! My cat must've walked across the keyboard and accidentally consented"
Ok, you're the judge, what's your call?
Should the dialogue force you to have to type: "I've read and consent to the terms ..." ?
If the company refuse, or if the user claims he was tricked into agreeing, then there is cause for further investigation.
And it's not going to be a judge from the start, but whatever organism is charged with compliance. Then, if they have a case, a judge gets involved.
But this discussion is full of examples of "consent" dialogues that clearly are made to trick users into making a different choice than what they want. In such cases showing the logs and dialogues would demonstrate that a valid consent was not obtained.
It's not a novel thing - for example, I recall that many years ago website opt-in patterns were being reviewed in the Ryanair case where the consumer rights agencies analyzed their website order process where a bunch of 'dark patterns' were used so that people accidentally "opting in" to things they did not want to. There's an administrative process that determines whether your process is honest or tries to cheat users into "agreeing" to things they don't intend to agree. In the latter case, you'll be forced to change how your stuff works.
i am sure there are many databases out there which i am marked as having consented it, although i did no such thing. the standard is to make it hard to express your desire to opt out despite the rules requiring entirely the opposite.
E.g. at the launch of GDPR a local major supermarket chain tried to use a bunch of dark patterns for their loyalty card program (mostly offline) process so as to continue their tracking, they were forced to change last year. It's clear that issues like that have a much larger impact on privacy of people than some foreign news website, and that's prioritized accordingly.
For the major multinational social networks, the delays are (intentionally?) caused by the lack of capacity in the Ireland data protection agency, as many of these multinationals have their EU HQ in Ireland because of tax purposes, so all their cases are being handled there and that means that enforcement for them is going to take a long time. But if I look at random local websites today and compare it to what was happening a year ago, the dark patterns are not prevalent anymore. They appear occasionally, but they're really rare now locally.