Tracking should be opt-in and consent should be freely given. If your notice is annoying enough that most people click accept (or if clicking decline is harder) then you are already in breach.
A lot of websites also consider analytics cookies as essential and don't provide a way to decline those which isn't compliant either.
These websites can be detected very easily by running a web scraper and looking for one of these non-compliant "consent management" solutions (looking at you TrustArc) and fining every single company that uses it.
It was a pre-GDPR case, but the court said it interpreted the them-in-force law in a GDPR-friendly way.
For a lot of websites, they are.
What the GDPR does do, quite successfully, is build a moat around Google so wide and deep as to minimize competition with them, because they're one of the few firms that can both (a) afford the engineers with the technical expertise to comply with the law while accomplishing their goals and (b) afford the lawyers to address the issue when they fail at the former.
Google is in breach of the GDPR as it stands, so no.
> afford the lawyers to address the issue when they fail at the former
Potentially, though again a clear-cut breach like theirs should result in a fine regardless of how much money they throw at the problem.
As far as building a moat, I'm not sure. Whether it's Google or a one-man shop, neither can accurately track users without being in breach. There is no moat that I can see, you either break the law or you don't.
I don't believe that is true. What is your source?
They were fined in Jan 2019, but are they still out of compliance? If yes, why are they not being continuously fined?
> you either break the law or you don't.
That's the result on the other side of a trial, sure.
Which is why good lawyers are so important.
They were fined on one specific thing and they maybe fixed it (or silently replaced with an equivalent, non-compliant thing once they went out of the spotlight), however they are plenty of other things they do that are in breach and those are not being investigated nor fined which is why we're discussing the lack of enforcement.
> Which is why good lawyers are so important.
True, but a good law should be one that you can't lawyer your way out of and so far the GDPR outcome of that is inconclusive given there is barely any enforcement at all.
Hell, at least around 2017, there were voices from Google that they considered ads to be unsustainable long term and sought to diversificate income streams.
The fun thing is, GDPR didn't actually introduce much change in law. It just gave, for the first time in history, existing laws a real set of teeth, even if they are still baby teeth.
So yeah, all that data companies had been vacuuming for no sensible purpose? It was always illegal
It literally is, by definition. Any business success has to happen within the legal context it exists in.
> The lawmakers made them fail and they either knew it was going to happen or were incompetent.
I could reword this as "the elected representatives of the people decided that certain business models were undesirable and anti-consumer, so legislated against them".
Yes, and they had business success until the rules were changed from under them.
>I could reword this as "the elected representatives of the people decided that certain business models were undesirable and anti-consumer, so legislated against them".
And I could reword this as "lobbying groups have bought our politicians and use them to enact laws to put our competitors out of business".
I'd say my rewording is closer to reality, because of course the two biggest ad networks increased in size while the smaller ones decreased as a result of this regulation.
it doesn't appear, 2 years in, GDPR passes that test. If the goal was to minimize "privacy violation" by FB and Google, it's failing. FB and Google are stronger than ever, but their competitors are starved out of the market trying to comply with an onerous suite of policies.
It's such a ladder-pulling set of laws it's surprising Google and Facebook didn't craft it.
> Good law doesn't "let companies opt-out;" it is crafted with consideration for what is already happening and the consequences of the law.
And sometimes the outcome of that consideration is "stop doing that".
Would you say that anti-violence laws are ill-conceived because they go against cartels/mobs' business models of extorting money from people under threat of violence?
The title of the article is "Two years in, GDPR defined by mixed signals, unbalanced enforcement".
So sure, maybe they're not complaint, but nobody is enforcing anyway.
EDIT: removed unnecessary pejorative statement from last paragraph
There is insufficient evidence attempting to comply with GDPR is worth the cost.
In most cases I bet the former isn't all that much. The latter is a harder nut to crack, with everyone trying to toe the line and referencing what other companies are able to get away with. Lack of good faith is a big obstacle.
One of the fundamental problems with GDPR is it contains a federated complain-investigate enforcement model. So your bet would have to apply to each of the EU’s twenty-eight members, now and in the future.
In that context, throwing up notices and calling a day makes sense. One can argue one tried. But not go so far as to potentially create new liabilities by interpreting these enforcers’ current and future preferences too strongly.
The number of people working at the respective national privacy regulators is appalling. All of them have an extremely scarce amount of privacy auditors that are qualified to extensively investigate privacy breaches. Even Ireland, which has a huge tech hub with the social media companies especially, has a scarce amount of them.
The Financial Times wrote an article about this awhile back, which tends to have good reporting on tech and privacy issues.
https://www.europarl.europa.eu/privacy-policy/en
The only two cookie options are "Accept" or "More". But the More option is broken and just brings up the same cookie notice again and again on my browser. It drops cookies on the browser regardless of whether you choose to accept or not (search your cookies in the browser for europarl.europa.eu, you'll find the unique "atuserid" and "atidvisitor" analytics identifiers it has set to identify you).
If that's the result on the EU Parliament's own website, on their privacy policy page, it's safe to say the EU doesn't actually care about privacy.
Currently the lack of enforcement allows non-compliant solutions (where accepting is easier than declining) to thrive so people get used to accepting everything.
Down the line, even when enforcement catches up and compliant solutions start appearing, users will still be clicking accept because they've been trained to do so.
This is unfortunately good for adtech/martech not just now but in the future, so all of those currently making your money on stalking users, don't cry, it's all gonna be okay.
https://chrome.google.com/webstore/detail/i-dont-care-about-...
You are a software company. Unless the server has the virus, I really don’t care.
Be thankful that GDPR exposes them, and look for alternatives.
If your contention is that it is immoral or incompetent to store any data except through some specific user interaction related to those data, sure that's an opinion.
But if your job is literally "tell me which other pages users go to after this one", it's not really that crazy of an ask.
The law seems to call upon you to make it conspicuous, but when you make it conspicuous it is annoying, the law then calls upon you to make it not annoying.
The better solution, in my mind, is just making cookie control features more visible in browsers. They work great, and it's the right place for this form of consent.
Malicious actors abuse the current circumstance, because it relies on there being a responsible party with collateral to complain against. This is one of those times where the engineered solution is better than the social one.
You said "the cookie thing just means that if I want to use these websites, I have to enable cookies so that I can dismiss the cookie dialog".
But if cookies are disabled, then there's no point in asking for consent. There should be no cookie banner in this case.
But the only way to determine if cookies are actually disabled in the browser is to attempt to store cookies, which is the thing you're asking consent for.
And even if there wasn't, attempting to store a cookie with a dummy value just to check if cookies are enabled does not break the GDPR for three reasons: first, if it's a dummy value it's not really personally identifiable information. Second, it's a functional cookie required for the site to work. And third, the site can just delete it afterwards the checking. No consent required in this case.
It's not hard. It's just a matter of checking for navigator.cookieEnabled.
It also highlights how, in general, this is a hard problem. Compliance with this law without creating a dead-static page has subtle complications.
But on the top of my head only display the dialog if the browser cache is cold. Could embed a timestamp in some cachable resource. (Edit: Perhaps this counts as a “cookie“ in the legal sense)
On our site, we ping whether that cookie is set before we load the rest of the cookies.
added: person down thread indicated that there's an API for determining if cookies are enabled for the host on your page's origin called navigator.cookieEnabled which I am shocked I've not seen nor heard of even once before today. Hallelujah. I now agree that everyone who doesn't check that before pestering people about cookies, when JavaScript is available, is literally satan.
But we were told anonymous cookies were totally fine and within the spirit of the law. If you hit the "Accept" button, you got a cookie that allowed more cookies.