As for server-side fingerprinting, the browser, upon the user's choice, would send the allow/deny information to the website, which is forced by law to honor it (as it is today).
As for server-side fingerprinting, the browser, upon the user's choice, would send the allow/deny information to the website, which is forced by law to honor it (as it is today).
It's legal to use cookies for behaviour such as login which is necessary but you need consent for tracking.
If a browser blocked all cookies until the user turned them on you'd have the choice of "no login" or "login works, but so does all the tracking".
Not saying the current state of affairs is good, it's awful.
That way, each cookie could describe itself as login, tracking, optional functionality etc.
You can then penalise on cookies that purposefully violate this, and allow the user to centrally opt in or out of each type.
I see you've covered that with penalising sites who mislabel. Who maintains this list? If it's the browser vendor remember which company owns the largest share in this market.
Otherwise have a way for the web site to trigger a browser-controled consent UI. This would be a one-shot thing and clicking "no" would trigger a spam signal. Too many of these and the web site loses its "ask for cookies" permission.
Cookies for anything not trusted have a lifetime of "until the tab is closed".
Don't be too rough on them. You should look for a viable and sustainable solution, not a radical GtFO doomed to end here.
> Cookies for anything not trusted have a lifetime of "until the tab is closed".
"until the tab is closed" policy isn't convenient even for the user. I tried it and reverted to "until the browser is closed" quickly.
There is zero need for standards, which won’t happen anyway because of the power Google has with Chrome.
The only protections we can have right now are client-side.
2) Pass a law making it illegal for a company with business in the EU to not honor a Do-Not-Track header, with a transition period of several years.
Step 1 is technically very easy. Step 2 is legislative.
Things like server-side fingerprinting must be enforced through legislation, e.g. it's against the law to track users if they've selected not to in the consent form.
1. When the user starts the browser for the first time, ask if they want to allow tracking cookies on all websites.
2. When the user visits a website, pass that tracking answer as true or false. Firefox and Chrome have buttons beside the URL already for 'Site Settings'. Allow users to override their global tracking setting with a per site settings there.
This would be infinitely better than the mess we have now, where every website gives us a pop-up with an intentionally confusing interface. Why can't I say 'No' to tracking once? Why do I need to do it countless times a day, each time navigating a new and confusing interface?
Would it be legal/ethical to allow automated pre-commitment to all terms and conditions that nefarious sites may choose to scatter around their pages, many of which won't have been written until after the user had ticked this "agree to everything" box?
> every website gives us a pop-up with an intentionally confusing interface
Any site doing this is breaking the law. Report them please.
> Why can't I say 'No' to tracking once?
Because sites which track you don't want it. After all, they're the ones who invented "cookie banners"; and they could choose to get rid of them by just, you know, not tracking people. Yet they don't.
Isn't everyone 'agreeing to everything' outside of the GDPR when they visit sites now, without the option of saying 'no'? Isn't everyone covered by GDPR being tricked into 'agreeing to everything' at the moment? Giving users the ability to disable the tracking aspect across all sites with one simple setting seems like a plus here.
> Any site doing this is breaking the law. Report them please.
Has any action been taken against a site for making their opt-out option more complicated than their opt-in option? Why try to regulate how millions of sites prompt users for consent instead of a few browsers?
> Because sites which track you don't want it. After all, they're the ones who invented "cookie banners"; and they could choose to get rid of them by just, you know, not tracking people. Yet they don't.
They didn't invent cookie banners, they added them because they were required by law. The same law could remove cookie banners and require the sites to respect a browser cookie.
If there's no option to refuse consent, then it's not compliant with GDPR. In countries which implement GDPR (mostly EU countries, but I'm the UK and our law implements GDPR but we're no longer an EU member) those sites are breaking the law (that country's implementation of GDPR).
If you're talking about those in countries which don't implement GDPR (or equivalent), then yes; those people are generally not protected by EU law.
> Giving users the ability to disable the tracking aspect across all sites with one simple setting seems like a plus here.
I agree. Again, good luck getting surveillance companies to pay any attention, or prevent them implementing technically-legal workarounds: "Just a moment! We see you've opted out of our advanced partner network. You may be missing out on the latest tailored brand recommendations! Click here to opt back in."
> Has any action been taken against a site for making their opt-out option more complicated than their opt-in option?
Not as far as I'm aware (and I can't see any on https://www.enforcementtracker.com )
> Why try to regulate how millions of sites prompt users for consent instead of a few browsers?
1) Browsers aren't surveillance companies (OK, not all browsers are; e.g. I'm pretty sure lynx isn't meant to be spying on me).
2) GDPR is bigger than any particular technology. It seems reasonable to make some regulation like "The public considers your business model to be exploitative; from now on this requires explicit consent." It seems less reasonable make a regulation like "The technology/product/process/service you provide could potentially be used by others in these specific ways that the public does not favour; you must provide this specific mechanism/option/etc. in case it does get used for that purpose". It's not necessarily a bad idea, but it would be a pretty big ask. Even looking at the current situation, how would this handle apps? What about tracking pixels? What about scanning nearby WiFi network IDs? What about research or hobbyist operating systems? etc.
> They didn't invent cookie banners, they added them because they were required by law.
The intent of the law was to reduce the prevalence of surveillance-based business models. They've always had the option to stop. That would be the preferred option, for those who wrote GDPR, for members of the public who don't want to be tracked, for members of the public annoyed by popups, etc. They chose banners and, to a lesser extent, to gaslight the victims of their surveillance into thinking that GDPR required all these sites chose to break their own UX.
> The same law could remove cookie banners and require the sites to respect a browser cookie.
Again, it would be nice, but I imagine there would be an industry established overnight to provide opt-back-in banners, under whatever guise they can get away with.
To who? What do I say? The issue with GDPR is that it's for all intents and purposes unpoliced and unpoliceable unless you happen to have sway with a local regulatory body.
I live in the UK, and ICO are toothless. Ive filed multiple complaints - inability to opt out, misuse of PII for advertising purposes, and each time have received a cookie cutter response telling me to report it to the company and respond to ICO if it's not to my satisfaction. That was the last I heard of every complaint, despite me following up.
I 1000% agree. And usability is not the only reason. I would also name the obvious responsibility delegation/abstraction principle and the original semantic concept of a web site: 1. the functionality every website is meant to have should be implemented at the browser level 2. no website (those using tracking elements included) should be required to have interactive elements (like the consent button) or off-topic texts (like the cookie notification).
We had this ( https://en.wikipedia.org/wiki/P3P ). It didn't catch on.
> It makes no sense that blocking cookies should be done via inconststent and dubious interfaces implemented by the websites themselves.
It also makes no sense that authentication should be done via inconsistent and dubious interfaces implemented by the websites themselves. Browsers have offered login prompts for years, yet they're usually avoided. Some sites hijack scrollbars, so it's not particularly surprising.
From the legal side:
GDPR is not about "cookie banners". It's perfectly fine to use cookies, or any other personal/tracking data, if the user's consent is implied. For example login sessions, shopping carts, game highscores, etc. would break without cookies or something equivalent, and those are features that users want, so we can assume their implicit consent for such cookies. GDPR is perfectly unobtrusive (for end users, at least).
On the other hand, users don't want to be tracked and surveilled. Hence anyone collecting personal data for those reasons cannot assume implicit consent. The choice is simple: either stop doing it, or ask for explicit consent. If you're seeing obnoxious "cookie banners", it's because the operators of those sites would rather mess up their UX with annoying crap, rather than entertain the idea of not being a creepy stalker.
From a pragmatic point of view, making it easier (or even automatic!) for users to give up their rights, in a blanket way to anyone who asks them to, just so unscrupulous corporations don't have to experience negative repercussions of their user-hostile decisions, would seem to defeat the whole point of GDPR.
If you don't want to see "cookie banners", ask the site operators to stop being creeps; that way, they wouldn't need to ask.