a) the cookies are necessary for technical reasons. This means you don't need to ask for permission
b) the cookies are for marketing, which means you must be able to decline without consequences
Half of the banners do neither of these things and are thus either unnecessary or insufficient.
Maybe I make that ballot measure myself, given so many "digital measures" having so much interest here already.
After moving from the US to the EU, I've thought about trying to use that right on my credit history in the US. I don't think it would work, but it would be entertaining if they even responded.
When does the right to erasure not apply?
The right to erasure does not apply if processing is necessary for one of the following reasons:
to exercise the right of freedom of expression and information;
to comply with a legal obligation;
for the performance of a task carried out in the public interest or in the exercise of official authority;
for archiving purposes in the public interest, scientific research historical research or statistical purposes where erasure is likely to render impossible or seriously impair the achievement of that processing; or
for the establishment, exercise or defence of legal claims.
The GDPR also specifies two circumstances where the right to erasure will not apply to special category data: if the processing is necessary for public health purposes in the public interest (eg protecting against serious cross-border threats to health, or ensuring high standards of quality and safety of health care and of medicinal products or medical devices); or
if the processing is necessary for the purposes of preventative or occupational medicine; for the working capacity of an employee; for medical diagnosis; for the provision of health or social care; or for the management of health or social care systems or services.
For more information about special categories of data please see our Guide to the GDPR.Nope - 'decline' has to be the default assumption for GDPR compliance. You only need the banner if you want people to opt in.
The web of 2020 has become a hostile and ad infested place. I miss the simplicity of the 90s, but it might be nostalgia bias.
For example https://www.telegraph.co.uk/ (right wing UK newspaper). In the pop-up it says "You can also review where our partners claim a legitimate interest to use your data and, should you wish, object to them doing so.".
If you click manage it opens with "user consent" selected, where everything is turned off. Click save means they're not going to start tracking you, right?
Wrong, if you switch to "legitimate purpose", you'll see that everything is turned on. All those ad companies claim they have a legitimate purpose to be tracking you, even though you have zero business relationship with them.
Unless the ICO hands out some very heavy fines to those companies, the whole thing's become a farce, just like the cookie law was.
I giggle every time I find this dark pattern thinking it is the modern equivalent of the ballots for the Austrian Merging referendum of 1938 [1]
[1] https://en.wikipedia.org/wiki/1938_Austrian_Anschluss_refere...
GDPR enforcement is approximately zero, to my knowledge, so I don't know if there's even really an answer to the question.
For what it's worth, Wikipedia gives the impression no-one really knows. https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
ICO, the UK regulator, seems to take a dim view of dark patterns, but they're only outright banned for children's content: https://ico.org.uk/for-organisations/guide-to-pecr/guidance-...
(PDF) Irish DPA's sweep of thirty-odd websites under its jurisdiction. Lots of good guidance here, but for the point specifically under discussion, ctrl+f "nudge." https://www.dataprotection.ie/sites/default/files/uploads/20... by the DPC on the use of cookies and other tracking technologies.pdf
(PDF) English translation of Greek DPA cookie guidance. See in particular the last page, "Bad Practices." https://iapp.org/media/pdf/resource_center/Greek_DPA_Cookie_...
I don't have a sign in front of my house saying "Beware of the dog", because I don't have a dog.
(See also https://knowyourmeme.com/memes/a-lot-of-questions-already-an... .)
You might instead consider asking people why they're asking, and figuring out ways to promote more widespread understanding.
Concretely: you might actively promote adblockers and tell people why they should use them. And rather than saying "we don't use tracking cookies", you could explain "here's why so many sites have cookie banners, here's why we don't".
(1) Identify the issue; (2) Quote all relevant rules; (3) Analyze the rules in light of your specific factual circumstances; and (4) Reach a reasonable conclusion based on your analysis of the rules.
This is how your company's legal team is making recommendations to management. You have to fight fire with fire. The only advantage your legal department may have over you is access to more comprehensive legal research services like Westlaw and LexisNexis. But at the end of the day, all they're doing is researching what the law is and how the courts are interpreting the law. Search for the right terms on Google, and you can do a pretty damn good job at crafting credible arguments. We don't need the lawyers always acting like they're at the top of the food chain.
(weak argument but somewhat funny).
Lawyers are ultra cautious. If you can -guarantee- that no one is going to magically add tracking/google analytics or some such to your site than sure, tell them you don't need the banner.
Also: it might be interesting to try and find some metrics on conversion impact for those stakeholders. You're making the product worse.
And at some point in pushing back, disagree-and-commit is the right thing to do.
That was his point. He was illustrating the absurdity he has to deal with.
Maybe the customer wants to not worry if some new developer is tasked with analytics and maybe this developer forgets about the cookie banner.
Some of the web sites I manage have sections in their Terms of Service outlining how we handle cookies, and store user login information.
These are web sites that store no cookies, and do not have user logins.
But whatever the legal department wants, the legal department gets.
When I feel generous, I chock it up to Legal future-proofing the situation. When I'm not, I call it trendchasing.
In my even less charitable mood, I'd call it copy-pasting ToS templates to avoid doing work.
Tell your higher-ups I hate them. I decide what my password is and if its secure enough considering how much I value a given service.
Yes, I do.
For example, I have a laptop that is airgapped from the internet. But macOS still requires a password to differentiate between users.
Fortunately, Apple permits four-digit numbers to be used for logins, and doesn't impose its own views on the situation.
* During user creation at least
Two options to solve disable the specific rule or change the password requirements. Sometimes the latter is the easiest in some companies.
The idea of implementing an annoying popup to support something you _might_ do in the future for any reason is madness.
And do they not realize that user credentials are a huge liability? Why would you want to support anything related to user identity if you don't need to.
Very few companies are large enough to have a "product design process."
In situations like this, it's usually some paper-pusher saw it on his favorite web site and thinks it should be on the company's, too.
Middle managers gotta middle manage.
Hilarious, stealing it!
Originally at https://news.ycombinator.com/item?id=23797037
I would go as far as to say it is wise to deal with it once and for all.
Especially since implementing the banner takes such short amount of time. Worrying about it will waste many times more brain cycles and once again there is always a chance someone forgets about it in the future and legal worries will be infinitely more costly.
I'd call it a legal fig leaf, but it doesn't cover up anything at all.