Functional cookies like shopping carts, logged-in user sessions, etc do not require disclosure nor consent.
Furthermore consent is only valid if it's opt-in (and not opt-out, so pre-ticked checkboxes are not compliant) and if it's just as easy to decline as to accept (so if it takes more clicks to say no than yes then they're in breach already).
Don't blame the EU for this, blame the website operators and their broken business models.
I believe the problem here is wrong advice leftover from the previous "cookie law" (which I agree is completely stupid) being repeated endlessly (either honestly or maliciously from the adtech/spyware industry to try and make the GDPR look more annoying to the users). I sometimes even see this wrong "advice" here on HN on GDPR-related threads.
Seriously, I wonder if adding those cookie banner impacted tracking in any significant manner, because it definitely significantly impacted the usability of the web.
The only world in which your statement makes sense in one where user tracking is assumed to be acceptable and something that must be done. Neither of those things are true.
As others have noted, a ton of sites seem to have just thrown the necessary JS on their site without actually seeing if they needed to, or if they did, if they could make minor changes that would remove the need.
From a usability/user experience perspective, now users have these popups displaying on some number of sites that they visit, often developed with the assumption that they will be accepted by the user.
Based upon some of the experiences I've had, I would say a number of teams neglect to properly test their sites as a user that has not accepted/dismissed the pop-up/overlay.
Through enough repetition the act of opening a new website and immediately clicking away the cookie popup becomes so automatic that people don't bother to read the disclosure, think about whether XYZ site should be tracking them, whether they want to consent or not, etc.
I myself am guilty of just clicking the damn thing without really thinking, and then I realize in horror that I opted-in by accident.
Replace it with a single "session token" value that you are allowed to set. Can only be created in response to a form post. No cross domain.
Make all the other web API stuff an smartphone-style opt in. "This app requires the following permissions: "Store private data in your browser. Only do this for site you trust as this can be used to track you." etc.
Maybe all the above can be made into an extension as a stop gap.
I'd imagine a flood of junk data would increase the cost of tracking.
Simpler rules on cookies: the cookie provision, which has resulted in an overload of consent requests for internet users, will be streamlined. The new rule will be more user-friendly as browser settings will provide for an easy way to accept or refuse tracking cookies and other identifiers. The proposal also clarifies that no consent is needed for non-privacy intrusive cookies improving internet experience (e.g. to remember shopping cart history) or cookies used by a website to count the number of visitors.
Browsers have provided this functionality for 10+ years. Why the law didn't target the user/browser level instead of the website level is beyond me.
I guess there's complication zero-knowledge proofs that could solve this problem, but they're too slow right now.
There was a standard for that, too. https://en.wikipedia.org/wiki/P3P. There's no reason why something similar can't be implemented now.
If anything maybe we should encourage having a "master preference" set in the browser, something like DNT (but not so easily ignorable) that just tells all websites on the user's behalf to only allow the absolute minimum number of cookies needed for the site to function. A small message on the bottom of the page could give more details or allow manual changes.
The regulation applies also to all sorts of analytics, fingerprinting, behavior tracking, user tracking, etc., which is far more prevalent and problematic than simple cookies.
How do you "delete" that?
OctoberCMS for example sets a cookie for every user and there's no way of turning this off, and lots of WordPress plugins just don't care with no option to disable this behaviour .
So most banners are just a notification rather than a choice. e.g. Continue to use the site and you automatically opt in. Which is not the intended goal for the law.
Of course they do, or one of their superiors does. Computers are physical devices that do what their operators tell them to do; it’s entirely reasonable to hold the operator responsible for what the computer does at their request. That includes the overt behavior of any software they choose to run, and they always have the option to choose different software or, in the extreme case, unplug the server and discontinue service.
Then the solution is simple: Stop using those CMSes.
>So most banners are just a notification rather than a choice. e.g. Continue to use the site and you automatically opt in. Which is not the intended goal for the law.
That is breaking the law. Generally, people should not do that.
Now we have GDPR which is legally enforceable (officially) so we could use the technical implementation that can automate applying it.
But it turns out that 100% OK is still not good enough. This whole thing should really be managed either by the browsers or by an extension and the consent request should come in a standard, machine digestable way (XML, json, what not). You could then just set your preferences once, that should work for most sites and every now and then (but less and less frequently) you'd be asked about what to do with unknown cookies on unknown sites.
In short, just because part of the industry is trying to circumvent regulation and because the current implementation is not the most efficient, we should not give up on the whole idea.
There are probably some context where “informed consent” is a sensible legal basis for processing data. But no-one in their right mind would freely agree to all this tracking that those pop-ups are trying trick you into. So instead of trying to make “consent” easier to give, just assume that is wont be given.
I can think of two or three entities I interact with for whom I might enter such a consensual agreement with. Neither are “sites”, and the web is not the primary way I interact with them, so a browser would not be to tool to maintain those agreements.
But I might not know what exactly 'consensual agreement' as a legal expression means.
BTW, this is pretty much the same issue as with ToS's. Some sites will try to DoS you.
Tracking required to provide a service for the user don’t require consent f.ex. So you could still get personalized ads from Amazon as service provided for you without needing explicit consent for the tracking as such.
Similarly “non-tracking” analytics don’t require consent either. If you by non-tracking mean more or less anonymous.
You only need consent to for processing PII that you don’t have a a legitimate interest to process.
Amusingly I've just followed a link on HN to The Economist [https://www.economist.com] - their popup offers a link to "manage your cookies" where you can untick huge numbers of them or click "Opt Out All". Great - did that, however on returning to the page found the popup still covers part of the page :-)
However, we must remember Hanlon's Razor.
Normal cookies required for the functioning of the website - e.g. session tracking, user input, etc. are exempted and don't require user consent.
See for ex. here (the official cookie guidelines for EU institutions' websites): https://wikis.ec.europa.eu/display/WEBGUIDE/04.+Cookies
Don't blame these BS popups, interstitials, click-through wrappers etc. on Europe, that's purely site operators' laziness, legal CYA (force these wrappers even where not required) and greed where various analytics and tracking cookies (which do require consent) are being deployed.
It isn't incidental that the penalty for being accused of willfully screwing it up is quite high: having to defend oneself against a 20 million dollar judgement.
You can't act surprised when people drive 55 in a 65mph zone because 'no one gets a 20 million dollar ticket for accidentally doing 5 over.'
When the world disagrees with what you think should be happening the problem is not with the world but with your understanding of it.
subjective and at the discretion of the accuser.
There's a saying somewhere:
Simple rules give rise to complex behaviour.
Complex rules give rise to simplistic behaviour.
I worked in web dev when these regulations were introduced, and any idiot could see that most companies would take the laziest, safest route to complying with them, in a way that would put a massive burden of inconvenience on the user.
If the EU was competent, they wouldn't have needed warning about this outcome. But they were warned, again and again and again. They chose to ignore it and screwed over their constituents for nothing.
What the EU did wrong is not the design of the law, it's the lack of enforcement. Enforcement of the law will fine anyone requesting consent in an annoying/obnoxious way and will clean up the current mess we're in.
If I happen to click a link on a news aggregator website like this one, then why would the website I visit (possibly for the first time) require my browser to accept cookies?
I don’t think GDPR demands “consent” for this though.