Only 9% of visitors give GDPR consent to be tracked
markosaric.com
markosaric.com
This means that users are de-factor forced to click "consent to all". I'm not even sure if that's legal.
Now, this was not some obscure small website, but the official Java documentation on docs.oracle.com! They use some third-party service for that - I just tried again, and though it worked this time, it still took 30+ seconds to submit my settings. I have a very hard time to believe this has technical reasons. Either this was made slow on purpose, or built by a bunch of morons.
/rant
Edit: jail time is not for anger obviously, but for intentionally swindling people. It'll be handled on a case by case bases obviously, but data is worth something, people who swindle you out of your data are like those who scam you in the street for your wallet, and as far as I know, there's jail time for that.
Yes, it appears to be. If you check the network tab of your browser, you see it makes about 8 requests. Then it waits for about 5-10 seconds and makes again 5 requests.
I think the data-money analogy isn't unreasonable, but you're overloading "swindle" pretty heavily here, in a way that defeats your point. Companies and people "swindle" others out of money all the time with dark patterns, and this predates computing by ten thousand years. Caveat emptor exists for a reason: the legal system is just too inflexible a tool to cram a person's view of "honesty in business" into.
Defining "making one side of an option an iota more of a hassle than the other" as criminal is broad enough that you're pretty much guaranteed to catch many honest transactors too. The law is a really blunt instrument.
If memory serves me, the EU does not Operate on the same legal framework as the US, so the assumptions I hear here: that the exact letter of the law they’re suggesting is worrying, is not How it works in the EU. They also don’t use case law to define exactly how something will be dealt with.
It’s a lot more fluid and ‘spirit of the law’y there.
I think.
When someone commits a wrong, the punishment is in part based on the amount of harm. You might feel that adtech causes small harms, if you look at harm against an individual, but adtech folks harm billions of people, every single day.
If you're Mark Zuckerberg, Larry Page, or Sergey Brin, no fine is large enough to make you regret your life choices. The only way to punish billionaires who get rich off harming others is to take away their time/freedom, the one thing they can't just buy back. As long as corporate CEOs can't get jailed, crime absolutely pays in this country.
Very similar to trying to cancel a spammy subscription (but that's not mandated by law, so)
Alternatively you get advised (also in the context of that 30 page privacy statement) to disable cookies.
That's the way we prosecute them.
Sure, we don't block accessing our site from a proxy, we just make you select the traffic lights forever. Is a crosswalk light a traffic light? Sometimes. Does it count if only the edge is in the picture? What if it's almost completely out of shot? Let's also slow down the loading of the images to a crawl for no reason and sometimes even if you manage to wait for all of them to show up and select them all correctly 20 times in a row we just say you fail anyway and send you back to the beginning.
There's no point in creating the line if you make the line endless. I'm not surprised Oracle of all places is doing what you've described, either.
I just went through a thing with Evidon where each of their opt outs is a JS-required redirect, and when you get to a company like Adobe, you have to click on a million things with a million disappointments.
It's intentional, and fuck you if you don't like it. Sorry, more like FUCK YOU if you don't like it.
Fuck the adtech industry.
Unfortunately, the only solution I found that fixes it is disabling ad and tracker blockers. They seem to break that prompt, though if you set them to be very aggressive, the prompt disappears altogether.
There are serious doubts if this is a complaint way to handle cookie consent.
All incentives for the site owners are against user interests.
No one benefits from users clicking to No Consent.
The user does. Or did you mean something else I am missing?
But, there is people that does not care for their customers nor the law. From safety food violations to illegal pollution of air or rivers. That's why we need more strict law enforcement for companies.
I have never had much luck using it. I just tried now to see if it's different I managed to successfully opt out of 10 / 123. Clearly intentional or all these billion dollar ad companies are running their servers on broken raspberry pis.
But yes, isn't there on the GDPR that tracking must be opt-in? I don't see how the pop-up is legal, and making the opt-out inaccessible is probably a large violation.
The GDPR gets this exactly right, and advertising companies are flagrantly breaking it. I'm hoping that there is actually some enforcement on it as well.
I wonder what results you would see for something like yahoo, the daily mail, reddit, or other sites that heavily rely on ad revenue, which attempt to force the user to accept the cookies through non-obvious no buttons, or long processes to opt out of cookies.
Can't wait until first party isolation is the default in browsers.
I found a very convoluted way of opting out: https://twitter.com/pos43/status/1001331147110957056
It is now 2020 and I would be interested to see if these methods have been changed to make them easier or harder.
I use everything I can to prevent tracking on my machine. But for a general solution for everyone, I don't know what would be the answer, but I don't think it's GDPR. If it's to work, acts forbidden by GDPR need to be handled very fast, and without interaction from user nor legal mumbo jumbo. Without a zero-tolerance policy, the cheap tricks will only grow stronger.
Edit: So apparently if you criticize gov/bureaucrats on HN you get downvoted.
It's just a question of how much the companies in question believe that the EU is going to come after them. Once the cost calculus shifts to being on the safe side it'd quickly turn into a norm, but it requires showing some teeth.
I can't stress enough how much of a game changer that is, by revealing the amount of third-party trackers on websites (in the order of up to 500 on a single site) alone.
So I guess GDPR works for me. There's a lack of enforcement, though. But that could change; for example, in Germany, bored law firms (eg those not having clients currently), or anybody actually, can print money by starting an "Abmahnwelle" eg. insist on GDPR compliance within a certain period of time, then sue any site for non-GDPR compliance, all the while being entitled for compensation of their expenses if they have a cause.
This is very much not true. GDPR isn't restricted to regulating tracking on websites. It also restricts and regulates what companies can do with the customer data they are in possession of. Through my day job I constantly interact with large enterprises (Fortune XXXX) that have vast amounts of personal data through their regular operations (banks, telcos, car manufacturers, airlines, insurance companies and the likes). Nearly without exception they go to great lengths to ensure the data is managed correctly, not used for purposes the customer hasn't explicitly consented to etc. This is as a direct result of the GDPR.
I also do my best to avoid tracking (Firefox add-ons, Hosts file). But up until now I had no leverage against any companies. Now they ought to be afraid when they play dirty.
GDPR is about a lot more than the tracking stuff though, it is about the personal data companies hold and are responsible for, your permission to request it, the risk of fines if they don't comply. Whatever dark patterns they use for tracking logic, they are still bound to use best practice security on the personally-identifiable-information they may hold and may be fined if they do not. That is what GDPR is mostly about, as I see it.
And I just upvoted for this piece of comedy:
> So apparently if you criticize gov/bureaucrats on HN you get downvoted.
It's useless because only a few people care enough to report these violations. If anything we need a campaign to get people to start reporting sites which violate the GDPR requirement of an informed opt-in.
? That the site exists in the first place ?
Why is it so hard for people to do business math and these conversations on HN never have anything to do with material reality of the parties involved?
It's understandable that we all want something for free - that's easy - but it's not understandable that we can't grasp how revenue is used to pay journalists etc.. We know they're all on the edge of going out of business and that thousands of news organisations are gone.
Whatever our 'personal cost' is, targeting ads definitely works, it makes money.
So that's the 'benefit' - you get people doing labour for you which otherwise, you'd have to pay for.
Structurally obviously we are now in a situation where “well targeted ads” can generate some revenue, and “well behaved ads” barely can. The future has to be one where dumber ads pay more because tracking isn’t technically possible and/or illegal.
If tracking means the website I enjoy get more money out of me, and that I get better ads for it, I'm all for it. For website I don't enjoy, I agree completely, I wouldn't share anything with them, but I would also try to avoid them, so essentially, I do that naturally consent or not.
Then they decided to track everybody, so the ads stopped being relevant and were just about stuff you were already looking for and for the pages you have already opened. Useless as it became, people stopped clicking and they had to start the dark patterns of mixing the ads with content, and filling the first page with it.
Now you are saying tracking is improving your experience, but you just said the ads are useless. Why is that? Are the original ads harmful? And you are protecting from that by surrendering extra information?
They don't want peanuts from solar charge controller companies, they want big money from say political campaigns whose ads or news articles will read "<opposing-politician> wants to defund solar" or "<our-politician> loves solar".
They never ask for consent to track on the general sense. So I use extensions to stop that.
It starts with "allow necessary cookies" enabled, and the rest disabled, and presents 3 buttons, a 2 small gray ones and a big green one, and unless you're REALLY careful, you'll end up accepting all cookies.
The text is something along the lines of "Cancel", "Save Changes", and finally the big green one is "Accept all cookies".
The trick here is that the small gray "save changes" button is actually the one you want, as the "accept all" effectively enables ALL cookies.
What then comes to my mind is the thought: "Well, would I try to do an ongoing delicate business with a well-known notorious asshole and trickster?". Obvious answer is "no".
So, in most cases, I just leave that site.
Shady sites that use dark patterns are about to go the same route.
And I have privacy badger, uBlock origins, as well as Pi-hole/PFBlockerNG (not at the same location). Our phones have ad blockers as well, though I doubt they’re as effective.
Does anyone have an example of a site with a clear opt-in/out? I'm curious about what's actually stored on my machine in each case. And of course it's not really what's stored locally that's the issue: it's what is stored on their server.
I wonder what's the best of shaming/reporting these examples and if an effective way exists[1]. If you have any ideas, sources, anything—please share.
GDPR consent screens are pure dark UX.
Yes, sometimes the information/actions are buried under a dozen of useless screens, but in some cases these changes are fairly subtle, like reversed the 'active' and 'inactive' states for Reject and Accept buttons on mobile, or things glitching, just a little bit. There's an obvious effort put into make things not only complicated, but also buggy.
So _fear, uncertainty and doubt_ all over again.
As someone who worked both on GDPR/Adtech/consent frameworks and privacy I still struggle to understand how some of these things are legal and what can we do to change it.
[1] Digression: Publisher pressure is one potential solution, but a limited one. Some premium publishers don't want to be associated with this kind of creepy UX. But, at the same time until we've completely killed cookie-driven behavioural targeting (and the alternatives, behavioural, not contextual) higher CPMs/ad revenue will keep the other publishers quiet. Ironically, behavioural targeting is mostly bullshit, and CMPs inflated, but that's a different story.
And yes, I'd assume the "phony consent" rate to be much higher, because in some cases I also cannot find the no button and/or accidentally tap on the huge yes button on my phone when my intention was to click the tiny no link next to it.
I hoped that he would repeat the experiment with a tricky one, like the horrendous forms served by Quantcast. In those, if you click "Reject all" nothing happens! How is that even allowed boggles my mind.
It is not. But GDPR is sorely lacking enforcement with regard to tracking consent. The last time I checked only 3 cases were brought up (all in spain), and all of those would already have been illegal before GDPR in my non-lawyer opinion.
If I understand correctly, this sort of trickery is forbidden by the GDPR, but so far no-one has seen any consequences for doing do.
This is precisely the problem with the GDPR to date.
Last August the ICO (British regulatory body) stated that you can't run Analytics such as Google Analytics without a GDPR standard of consent. They've yet to enforce this despite tens of thousands of non-compliant websites.
I don't wonder about their numbers, it's obvious their numbers are good for them. What I wonder is how are they getting away with something that is clearly illegal.
As already explained, in properly implemented GDPR survey, it should be equally easy to accept, decline or ignore tracking, with the default being decline if user doesn't give explicit consent.
I think both the old cookie law and the GDPR kind of (directly or indirectly) include that case†, and sites know that they don't even need to display the dialog if they receive the header.
† the consent (or rather, intent not to consent) is explicit, and although non-interactive at the site level it was interactive at the browser level until MS defaulted it to `1`. Now I'm wishing it were like those notifications/location/webcam/mic access and the dialogs were required to go through the browser itself.
Then I think that's the best kept secret of the industry.
Oh, there's nothing like that in the so-called "HTML standard"? Maybe, just maybe, Google being the standard body might have something to do with it, when Apple have been blocking third-party cookies for years now [1], and is in the progress of banning browser APIs that can be used for fingerprinting.
Best of all, this might rollback all those HTML5 APIs that have no business being shipped with browsers, and bring back the web content we want.
[1]: https://webkit.org/blog/10218/full-third-party-cookie-blocki...
It would be much better to make a browser-side dialog like it's done with location tracking and desktop notifications, and also provide a checkbox in the settings. Most importantly it would take away control from shady websites to implement it on their shady terms(though admittedly giving that control to Google's browser may not be ideal either).
This was one of the worst dark patterns I've seen. PS. The app was MyFitnessPal which i registered on recommendation but that felt so shady.
In summary, I could see how that might take a minute or two without a requirement for evil.
i can't remember the last time i used my real info or email.
although there was a case just last week where a site "needed" my phone number. in 2 seconds flat i decided i didn't need that service.
of course without a legit email you can't, or it's much++ harder for account recovery, but i can live with that.
Depending on websites to limit tracking by on their own is very difficult, since it is inherently against many websites' business model. They will keep trying to bypass the rules.
The average user simply cannot switch browsers.
The likelihood of encountering a website that breaks even switching from Chrome to Firefox is too much for any normal user to want to bother for just these purposes. They'll switch back the minute they find a website that doesn't work in their new browser, if they even get that far.
So unless you're suggesting "Chrome should make it more obvious how to clear cookies automatically and/or not accept them at all" (which seems like quite a UX challenge itself), saying "just tell everyone to switch browsers" just isn't going to work I don't think.
EDIT: to finish the thought -- yes I agree, browsers should provide users with choice, and switching browsers should be available to anyone who is unhappy with the way their browser treats their data, but that can't be the only way -- otherwise, the average user will get left behind.
At least browsers don't have that inherent agenda against their own users. There will always be a Firefox which genuinely strives to serve its users, rather than exploit them.
Just click the lock next to the url in the url bar.
The GDPR popups is not nice in theory or practice.
Or the sites that don't bother with compliance and just show a message to the effect of 'this site operates under a jurisdiction that may have different privacy laws to your country' and leaves it at that.
The first option, redirect, is not GDPR-compliant, because then the "consent" cannot be considered freely given, and thus is not valid
The second option is really borderline, and could work out for a US-only news website, for example (arguing it doesn't cater to European residents), but would be non-compliant for a business which knowingly serve European residents.
I don't quite understand the reasoning on that one. In Europe, and pretty much everywhere else, there are a bazillion interactions every day in the form of one party offering to provide some good or service only if the other party agrees to something.
For example, the grocery store will only give me food if I agree to let them charge my credit card.
Why is consent considered freely given when I give someone money for a good or service because if I do not do so they will not provide the good or service, but not freely given when I click "agree" on a privacy policy disclosure because if I do not do so they will not provide the good or service?
Why? Presumably because most users don't see the real cost of giving away their personal data (either they never recognize the cost, or see it too late).
To make sure this is held up, the GDPR uses some tools; one is that consent is freely given, the other is ban on tie-in sales: you cannot demand PII from users that isn't necessary for the service you provide.
If you provide news or stories as a service, you cannot demand location data from your users, because you can provide the service without that.
For someone to use your personal information, they need to have one of the 6 legal basis to do so under the GDPR. One of those legal basis is to have a contract with you (in which case, the contract will define what's allowed and what's not). Another of those legal basis is "consent", which is the one being the most discussed, as it is generally the only one ads can hope to use, so let's ignore the 4 others (legitimate interest, public interest, vital interest, legal requirement, you can easily see why trackers for ads targeting don't fit any of those).
It is generally admitted (or at least I think it is, feel free to dig around for a better source for or against that assertion) that visiting a site is not entering into a contract (probably because a contract has to be fair, and giving up personal information without your knowledge just by visiting a site isn't actually a fair? I don't know that, IANAL).
That means the only legal basis ads companies (or the site that host them) have to use your personal data is to have your consent, which is strictly defined in the GDPR (and other posters have discussed how this definition is mostly ignored)
The grocery store doesn’t need to ask if you consent to paying for an apple because if you didn’t consent there wouldn’t be any transaction to perform.
Now if you paid for your apple and the cashier said okay hand over your phone so I can poke around a bit because there’s some fine print that says by nature of walking through the front doors you agree to allow the store to look through your phone. Did you consent to that? Of course not.
Consent wasn’t “freely given” because the store is requiring you disclose information (the contents of your phone) as a condition of service (you can’t even walk through the door without “consenting” let alone make a purchase) and that information isn’t necessary in order for the store to complete the transaction.
GDPR says they have to ask you first (usually in the form of a giant irritating banner as soon as you walk in the door) and that if you say no they have to let you buy your apple anyway.
"When assessing whether consent is freely given, utmost account shall be taken of whether, inter alia, the performance of a contract, including the provision of a service, is conditional on consent to the processing of personal data that is not necessary for the performance of that contract."
Preventing you from seeing the page you request if you do not consent seems a lot like the provision of a service conditional on consent. Obviously, that's for a judge to decide, but the law seems very clear from my perspective (IANAL, that's not legal advice).
- consent requires, among other things, that permission be given freely;[1]
- so, if coercion is involved then consent does not exist;[2]
- and, preventing user access to content unless that user agrees to be tracked is likely considered to be coercive.
Therefore if a user grants permission to be tracked only in order to gain access to that site's content, that granted permission would not be considered consensual because that permission was not given freely.
(the above is not legal advice but I do have a law degree; I also work for a NGO that produces apps that teach people about consent)
----- [1]GDPR Article 4(11) [2]GDPR Recital 42
That's potentially but not necessarily compliant. To a large degree, it depends on the intent of the website's data controller.
* GDPR Art 3(2) discusses the territorial scope of data controllers that are not in the EU. Their data processing falls under the GDPR if they are offering services to people in the EU.
* GDPR Recital 23 discusses potential factors that indicate an offer. Blocking EU visitors is not necessary: “Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.”
* The EDPB has issued further guidance on the territorial scope. In their guidelines 3/2018 [1] the spend a lot of ink on discussing this “targeting criterion”, and provide some clear-cut examples. Of course, that falls short of actually interesting examples of edge cases :)
[1]: https://edpb.europa.eu/our-work-tools/our-documents/riktlinj...
And usually clicking "yes" will do away the banner in the most hassle free way.
I am surprised the number is so low.
I surely click "Yes" on any banner immediately without reading it.
My guess is that the number was so low because his banner (by its simplicity) looked unusual enough that many people read it.
With the typical spammy pseudo consent banner, the number would probably be much higher. Even without dark patterns. People are just trained to click yes.
During the initial stages we had worried that consent rates would be low, and while Germany was "low" at around 70-75%, we found that overall consent rates across all countries were 90%+ with exceptions for Germany, France, and a couple other European countries. This was consistent across both the application and our marketing website, and across 10s of 1000s of users.
So while I don't doubt that the author ran an experiment and got these results, I strongly disagree that you will get "only 9%". Specifically, these lines in the blog post:
> And if you give them an easy way to ignore your banner or to say no to be tracked, most of them will simply do that.
> Most web users will simply select “no to tracking” once in their browser and the browser will block all the trackers for them as they surf the web.
is not correct, at least from my experience, and it absolutely can't be used as a blanket statement like this. Of course my anecdote is, well, anecdotal, so take it with a grain of salt, but I don't think it's fair to say that users will simply reject it no matter what, and it really depends on both context and trust levels.
Why not outright outlaw opt-out tracking and be done with this silly state of things?
There are legitimate uses of tracking and any company would still be able to provide it for the users, but you would have to have legally binding contract and opt in for the service.
> saving a cookie no_consent=true does not require consent by the user. that's the type of cookie easily classified as functional/necessary
It looks like an unusual choice for the website. Assuming that the intention of the website is to use all the trackers that it is asking to use going out of their way not to ask the user to be tracked seems counterproductive.
Sure the website is also interested in not annoying the users to death, but then it sounds a better idea to offer less invasive prompts and more informed choices than a blanket yes/no. Here again I feel like gitlab made fanstastic choices for their prompt.
As sad as the current ads-powered internet is becoming I haven't seen any promising viable alternative, and sure non-tracking-based ads is not the same thing as having no ads, but it significantly moves the needle in that same direction in terms on revenue.
A viable alternative: show non tracking ads and see if it keeps the lights on, otherwise shut down?
I'm not sure that'd be viable in general, like what would the economic impact globally if all websites that barely can manage to keep the lights on today because of effective ads just disappeared? Maybe the impact could be even positive, like by disallowing politically very-targeted ads, among all other kinds of targeted ads, maybe we can prevent idiots from being elected, but if I had to guess I'd say I wouldn't like to see those websites disappear.
Like imagine if YouTube disappeared because it can't make enough money to host all that staggering amount of content.
Tracking is also not required for advertising, it only (supposedly) increases the effectiveness of it at the expense of the user. A more apt metaphor would be "restaurants are using cheap toxic chemicals to increase their revenue".
Tracking is not strictly necessary for having ads, but for having _effective_ ads I would argue at least in some cases it makes all the difference. For example I don't care one bit about cosmetics, if a cosmetics company advertises to me it's going to waste its money, and if the company has an increased chance of wasting its money than the ad space is worth less, meaning the website owner gets paid less, meaning that eventually after some threshold is reached offering the content or services via the ads model becomes unsustainable.
Perhaps tracking users is more effective, perhaps it is not. Regardless, boundaries need to be set to enforce ethical behaviour if the unethical behavior is more profitable. If that means certain companies or business models won't survive: so be it. There is always a trade-off to be made between ethics and business. After all, the exact same arguments could be made against outlawing child labor or any of the past atrocities businesses committed in the name of profit. Businesses that cannot survive ethically will die to make room for businesses that can.
I don't want that one piece of furniture I (or my SO using my computer) looked at on Wayfair to follow me to the motorcycle website. I definitely don't need an ad empire following all of my activity on the internet and knowing that I'm a 35 year old man that wants to buy a motorcycle, needs a plumber, wears size 32 pants, and looks at green couches among all the other data they are collecting.
So companies can still have effective ads on relevant sites, ad networks can still facilitate the in-between, and users don't have to be tracked. Advertisers already use Google AdWords to show ads to people searching for specific keywords, this is just an extension to show ads to websites with specific keywords. Websites are already working with keywords for SEO, it's not even extra work for them.
You might enjoy Bill Hicks’ take: https://youtu.be/tHEOGrkhDp0
You can probably count the ethical, law-abiding adtech firms on one hand.
Of course, I can only speak for the apps I've been building and SDKs I've used.
It's just not well enforced yet.
The interesting thing about GDPR is it officially bans "opt out" tracking cookies - you need someone's consent, although lots of sites interpret that in a way which ... let's just say if they applied the same standards of consent to their private lives they'd very quickly find themselves at the center of the next #MeToo campaign.
GDPR does allow you to make the "Yes" and "No" buttons the same size, so "equal choice" rather than "opt in" - maybe that gets you better conversion rates?
[1] http://www.behaviouraldesign.com/2015/08/11/why-99-of-austri...
Gorhill’s browser extensions are a must when browsing the web these days.
Is it really less disingenuous to place it to fit what HE wants versus what SOMEONE else wants? Both still abuse this mechanic... it's just the goal that we agree with.
Only 1 person out of the 774 who opted into being tracked drilled down and made a more granular choice. That visitor said no to stats but said yes to advertising and social media."
This seems weird to me. Why would you block google from getting the statistics, and then give it to them anyways via doubleclick?
So my guess overall is that GDPR is not enforced at a larger scale and we are very far from enforcing the requirement to have "Accept"/"Decline" buttons equally usable.
instead let's talk about solutions.
safari's cookie and localStorage policy is great and automatic. beyond that, firefox containers are good, albeit effectively limited to isolating a few "top sites" like FB. and then of course, UBO, ABP, ghostery and the like.
it's actually not that hard to take a few small steps (or just do the default things on MacOS) to stop this from affecting you, without impacting your (ahem) user journeys.
first-order fixes are easy. now let's get ahead of these assholes and work on fixing fingerprinting.
TFA is ironically quite interesting in that it itself is SEO content, aka an ad. targeting those that care about not being targeted. i, for one, have bookmarked it.
EDIT: Thought about it, and if you only record the button click and does not identify the user, it works, and I am wrong! In general ePrivacy is very restrictive, only about access to terminal and not about personnal data ( and btw PII is not a GDPR thing, we say personnal data), but here it's ok! So yeah, no to me!
One of these is that the processing is necessary for the performance of a task carried out in the public interest.
You could probably make a colorable argument that research for publication into the effectiveness of GDPR implementation approaches is in the public interest.
If you need a reminder every single freaking time you visit a website, that's your problem not the government's. If you don't want them, turn them off in your browser, install a blocking/auto-wipe extension, use lynx, whatever you want.
Now, I completely agree that websites should clearly state what they are doing with data the user uploads, if it is end-to-end encrypted, etc. The user otherwise has no way of knowing, and it is material to assessing the accuracy of the often-BS "military-grade security"-type marketing and other claims like that. But there is no need for users to "consent" to using a public API of their web browser.
Edit:typos
That said, you do need to inform users of who specifically they're sending the data to (and what they're going to do with it) in the consent option. So "Yes, track me with all your unspecified partners" doesn't quite cut it for the yes option.
However, consent under the GDPR must be specific. That means the user should be able to consent to or withhold consent for individual processing purposes. Analytics would be one purpose, personalized ads another.
Note that under EU cookie laws you don't need consent for cookies that are strictly necessary for the service requested by the user. E.g. using a cookie for dark mode preference, for a shopping cart, or for the consent status itself is perfectly fine without consent.
for websites that do not allow me to navigate or do not have a refuse button, I simply navigate away.
I guess where the article falls flat is where the author says a "proper GDPR content banner" was implemented. No online publication will do this. At least they will trick you with button colors, or some kind of double negative mind trick. Sometimes they will require you to tick all the checkboxes out.
GDPR was a good idea from the start but it's implementation is rather dull - they shifted responsibility to each country without penalization for relaxed enforcing, and now there are countries like mine (Portugal) where we have less than a hundred fines.
I am exactly the same. I use UBlock Origin and Privacy Badger so pretty much nothing gets through anyway but just to get rid of the banner, I click on OK.
However, that being said, I only do it if the other choice is "Manage Preferences" or something equally vague: If I am given a clear yes-or-no choice, I always choose "No".
And yet the cookie is still there and can be used to track you. They don't need to serve you adds to track you. A simple check for the presence of the cookie is enough to track.
I see no reason to turn off Performance and Functional in most cases.
I agree with the broader point, but principles of a nice user interface also apply here.
Unless the website tricks you into clicking a button that you did not intend to click (like with your double negative example) it is not a trick. If you do not read and just click the most colorful rectangle to make the pop-up go away that is the user problem even under the GDPR
[1] https://marvinblum.de/blog/server-side-tracking-without-cook...
Accepting to GDPR / Cookies: This should be some kind of a web standard , built inside a browser so user can accept it once, ignore or whatever, but seeing this on every website drives (drived) me nuts.
From a GDPR and ePrivacy perspective it's clear that opting out needs to be just as easy as opting in. Most websites violate this principle as opting in is in fact way easier, and often the UI is designed to be deliberately confusing to the user.
IMHO the consent problem one of the central unsolved issues in privacy though, as most people would not opt-in to tracking if they were given a real choice.
Tracking effectively is getting harder both technically and legally; and that's a good thing long term but leads to chaotic and desperate behavior short term.
Long term, there are three ways to adapt:
- drive users to apps instead of browsers. E.g. Google and Apple do this serve most of their news via apps where they control the ad experience, tracking, and user signin. There are no anonymous users there. GDPR still applies of course but practically speaking users only have the choice whether to use it or not. And none of the legales specific to browser based things like cookies apply. - tap into other sources of revenue (subscription based, sponsored, donations, etc). Ad revenues have in any case been declining for lots of news sites so this is something they need to do in any case. - switch to non personalized advertising that can still be lucrative if you have access to large amounts of users. E.g. most big brands still advertise this way and still lots of money floating around here. No cookies required.
Those websites that are usually all about streamlining and reducing friction to a maximum suddenly don't hesitate to trick me into a maze of slow-loading menus with weird conventions and a purposefully broken and confusing UI in an obvious attempt to trick me into opting in by mistake, even though the mere fact that I clicked the "more options" button means that I'm almost certainly looking to opt out.
These are tactics that I expect to encounter on shady websites, not some of the biggest websites in the world.
Advertising is a cancer that offers next to no added value in our hyper-connected society. Tricking people into seeing ads to trick them into buying stuff they don't need has become the foundation of the web economy. An utter travesty that puts our industry to shame.
Not everyone can pay for the content they consume. Some people are poor, under 18, live in a country where Visa/Mastercard isn't widely supported or can't pay for some other reason. Internet has made the lives of those people much, much better. They definitely prefer being tracked over having to pay for Facebook, Snapchat, Youtube and all the other sites they use. GDPR forces providers to provide their services to customers who opt out of tracking, and most of them will. That means switching to a payment-only model is going to become the only viable option, hurting a large part of the population.
The "just force them to pay" attitude that I often see here is extremely elitist. For someone making six figures, being tracked matters. For someone barely scraping by or without a credit card, that's an acceptable price to pay for all the goodies they get.
Or, they don't ask anything, and just set their cookies. (case in point: each and every status page by Atlassian Statuspage)
I tried to make an open source extension to try and do it for me: https://github.com/pyepye/GDPR-opt-out
Although I hit a snag where some GDPR banners / buttons didn't return when using `querySelector` in the extension but do when you use the inspector / console and do it manually.
Does anyone know why and how to work around it? It was always something I wanted to know why but didn't find the time to dig into (and wasn't important while using ublock origin)
Other point: third party hosters. It's good to see you as the website creator put effort into GDPR compliant behaviour! Did you also include Netlify and your GDPR-provider into the evaluation? Do they use additional tracking technologies?
btw, your post was copied to https://www.facebook.com/BloggersWorldToday/posts/6238368718... fyi
Is the writing on the wall? GDPR came into enforcement over 2 years ago, and I'm not aware of improvements having been made with respect to clarity, because I'm not aware of any punitive measures actually having been taken. Would love to hear comments to the contrary.
The GDPR is and should be effectively a ban on tracking ads once sites actually comply (or, in many cases - leave the EU market or go under instead).
Whether the alternative is a good solution for paying for content or if it’s the end of the majority of content online isn’t really interesting as both outcomes are better than the status quo.
And once set, the browser should pass the user decisions to the website, and enforce those that can be enforced locally (at the browser level).
Privacy Policy should be enough for server logs (without PII). It would be nice to have standard Privacy Policy though (like we have MIT, BSD licenses).
I need analytics because this blog pays the bills. I need to see what works and what doesn't. When building partnerships, I'm usually expected to share some numbers with them. It also lets me spot issues with the website.
I do not use Google Analytics but it looks like it is possible to disable Cookies [1], anonymize IPs, disable data sharing with google [2]. Effectively making it almost third party server logs analytics (no consent required). Would remaining functionality be sufficient for you?
[1] https://law.stackexchange.com/questions/36105/can-usage-of-g...
[2] https://law.stackexchange.com/questions/35528/is-it-really-p...
Would be interesting to see how the consent rates for big offenders like techcrunch, newspapers etc are. IIRC there were specific studies about which brands are trusted by consumers, and Comcast et al. didn't fare all that well in those.
So I guess exactly zero visitors opt out there in the intended way. So 100% "opt-in".
I tried to opt-out from all to see how many cookies would be set anyway but gave up after 5 minutes.
https://mobile.twitter.com/Joe8Bit/status/115631296526570701...
And I'm really irritated that I can't access local news sites in America because they aren't compliant -- so they blanket ban European access. That's deeply problematic.
The usual answer I get when I complain about this is either "It doesn't happen to me" or "They wanted to steal your data. You're better off without being able to use their site."
I've yet to be convinced by either argument as a European. It's almost like a knee-jerk reaction by some Europeans that if Americans do something we don't like then they're automatically in the wrong.
Personally I like GDPR more than no-GDPR and think that it would be nice if the US had a GDPR compatible regulation (as in the EU and the US diplomatically agree that it is enough for US company to respect the US regulation and for European companies to respect the GDPR to be compliant under both). On the other hand as laws stands I appreciate that they take this law seriously, even if not in the way I would like most.
Overall I do not think that losing access to local US news sites warrants remaining in a GDPRless world
HackerNews is a U.S. site, and it works fine in Europe
edit: sorry, replied to the wrong post
1) Accept being brightly coloured and decline as white so its less prominent.
2) Having accept all be a simple thing but decline being a more information that requires turn lots of individual things off.
3) Requiring the decline to be individual across hundreds of individual cookies.
4) Clicking accept all is stored and used forever but decline is asked everytime you come back to the website.
5) Having the decline process take minutes to complete as if significant processing is required.
6) Having the default be acceptance.
I think breaches of GDPR are the normal, 95% of the websites I see these popups on is breaking the law in some way or another and at this point have been doing so for years.