French watchdog fines Google, Amazon for breaching cookies rules
fr.reuters.com
fr.reuters.com
This banner did not provide the user with any information regarding cookies that had however already been placed on his or her computer when arriving on the site. The information was also not provided when he or she clicked on the button “Access now”. """
Wow. I though those reminders were about some updated policy, I didn't realise they were supposed to ask for consent.
Could someone try standing with a sign saying "A reminder from me" in the google offices reception for 2 minutes and then walk out with whatever wasn't bolted down to see if they themselves consider that an adequate way to ask for consent?
That would be hilarious. But I think they know what they are doing (i.e. using dark patterns).
I've seen this banner, knew it was related to the RGPD but haven't figured out how to opt out and to not accept.
There doesn't seem to be an easy way. A lot of their proposed opt-outs rely on either disabling cookies browser-wide, installing an extension or creating/signing into an account and customizing your advertising preferences there (which means providing them even more info as part of the account creation and relying on their good faith to actually opt you out).
To the best of my knowledge none of these things are compliant with the GDPR:
* consent must be granular, so browser-wide cookie-blocking doesn't comply because disabling cookies entirely means you lose functionality (the GDPR mandates that you can opt-out of non-essential tracking but retain all other functionality)
* mandating that people register for an account might run afoul of the "data minimization" principle (among others), meaning that you must collect the minimum amount of data to fulfil the required purpose; asking people to register/sign into an account (thus providing even more information) just to opt-out of non-essential tracking seems non-compliant
* consent must be opt-in (seems like cookies were placed before the user explicitly agreed to it)
* it must be as easy to opt-out as it is to opt-in, yet in Google's case the opt-in is one-click away (though it doesn't matter since apparently they set cookies even before the user clicks that) but opt-out is way more involved (and relies on reconfiguring the browser)
"consentId: abc134" then looking that up in or even "consentDenied: exact timestamp" could be used to identify a user so would require consent. I suspect lots of companies want to use the second so they can choose to bug you for [more] consent at a later date, or choose to interpret the first as not allowed in case bugging the user again enough times does get consent.
I've worked hard to block the HTML div with ublock origin, but recently it's messing with the html, adding overflow:hidden at weird places. I've added a rule to fix it but it's not a silver bullet.
Youtube videos must be restarted because of the consent thing pauses the video or ask to sign in.
I'm wondering if I've been noticed by Googles ad engineers because they must have developed tools related to this rgpd thing.
On Facebook it's even worse.
To be honest it's a fun game of cat and mouse and I'm so happy to have Firefox, containers, strict mode, etc.
Amazon is fined 35 millions for similar reasons, but the amount is lower because they acknowledged and fixed the issues in September 2020. [2]
[1] https://www.cnil.fr/en/cookies-financial-penalties-60-millio... [2] https://www.cnil.fr/en/cookies-financial-penalty-35-million-...
1) To get people to quickly simply accept all cookies because time is money and its too complex.
2) To get scare them away. If you don't wanna be the product, at least save us money.
3) To make them waste their time (= money) on their privacy.
Boss won't like #3, neither does the wife. So its like #1. Sure, whatever. Or, those who stick to their principle and can refrain their curiosity or need for information to go for #2.
The advertising industry (I almost wrote undustry, go figure) is so rotten, that I will gladly just shell out some money to buy something of quality instead. I just gotta be sure it isn't money wasted ie. that I (or whoever I buy it for) will use it. With advertising services which are free, the real product is also the demo, but their model is to get you hooked.
Which is to say, the punitive fines are not enough for them to not play games with the rules... but once they're caught they do have to fall in.
This demonstrates the need for constant enforcement diligence by regulators: These companies can and will continue to flagrantly disregard the law unless regularly checked.
A session cookie, especially after a login, may not require consent at all. Describe in your policy what personal data, if any, is tied to the session, and what you do with it. Most places collect and process only what is necessary to deliver a service and fulfill a contract. Let users read this policy and possibly contact you to make changes to their data.
Of course, this is not what happened here with Google and Amazon. In the meantime it is so unfortunate to see cookies becoming "illegal" taboo.
The issue should not be phrased as "breaching cookie rules", as murdering someone with an automatic weapon is also not discussed as a "violation of human tissue guidelines".
Lawyers are unlikely to take kindly to arguments of the "Well technically the advertisments are an integral part of the site", that will surely be raised in response to this. This is why the law is not code and gets interpreted by judges.
Those are the concerns with GDPR, you can do whatever you want if you are explicit about it AND have consent of the user.
So they are fine with taking French money, but want to be above their laws?
One of the things that stops GDPR from being a total clusterfuck is the so-called "one-stop shop mechanism." Each country has its own regulator, so GDPR is enforced by 27 different government agencies. BUT, anyone only ever has to deal with one. For EU residents, the regulator of the country where they reside. For businesses, the regulator of the country of their primary establishment. Regulators are supposed to cooperate in such a way that a company has a single, local point of contact.
(Related: If US companies push for federal privacy regulation, it's because they would rather have 1 law to follow rather than 50 different ones.)
Almost all US companies establish their EU subsidiaries in Ireland for tax reasons. As a result, the Irish regulator is basically in charge of GDPR enforcement against US companies. This is... not ideal. Ireland a conflict of interest, because of the tax stuff.
(I'm not an expert on this. My understanding is that the Irish regulator seems to be operating in good faith, but is under-funded, and is going up against the legal defense teams of Google, Facebook, Amazon, etc., simultaneously, all on its lonesome.)
Several of the larger and more privacy-focused countries, like Germany and France, have been openly critical of Ireland's slow enforcement of US tech giants. In the past, CNIL (France) has said that Google's establishment in Ireland is a legal fiction rather than a legitimate business establishment. But if this gets appealed to an EU court, this is going to be a huge point of contention.
(Possibly the only point of contention, because I don't see any way that Google's actions are in compliance with GDPR/ePrivacy Directive.)
Taken from: https://www.dataguidance.com/opinion/eu-one-stop-shop-under-...
It could be that Ireland did not react within the one-stop-shop allowed time frame, freeing France to start the procedure.
This is the EU we’re talking about. It’s a bit weak on right to repair at the moment. But on warranties and digital product returns, we have some pretty strong and effective protections.
You get a fine contingent on not following the law, so... just follow the law? Fines need to be big for big corporations if they are to pose a risk worth avoiding.
> Do they go to the users impacted - nope.
As with any fine, it goes to government, which means that same expenditure requires less taxes. So it gets shared among all french population. Which is a good proxy for “users impacted by google cookies in France”.
> Do changes happen as a result - slowly if at all.
So if 2 companies are fined for not complying with a law, the problem is that the law is overly punishing / fining does not work? It would seem the other way, that the fine risk was not big enough!
> who ends up paying for it...the users/people..again.
Which are also the ones that receive the money, through their government.
[1] https://abc.xyz/investor/static/pdf/20201030_alphabet_10Q.pd...
In France, as we see here in the difference in fines between Amazon and Google, the fines are not a flat rate: repeated offenses lead to harsher sentences.
On one hand, the data harvesting targeted by cookie laws and associated privacy stuff is important and legislators/regulators are right to target it.
OTOH, effectiveness is pretty marginal. There have been some (minor) gains on disclosure. Somewhat better progress on data selling/sharing/security. But, no real gains on consent, which is a big part of the regulatory effort and this specific case. Between dark patterns, take-it-or-leave it propositions and predatory defaults... I don't think most people have a more censenting relationship with amazon or google than before.
Regulators (also prosecutors, often) tend to focus enforceability on easy to prosecute, legible stuff. "Must contain small print" rules. This is how we end up with such meticulous small print norms for advertising pharmaceuticals, financial products and other regulated industries.
Fines themselves do not deter profitability monsters like this and the "fix" is going to be an update to the popup, small print, naming of buttons and other things that don't really matter much outside of a legalistic perspective.
I'm all for the goals of these efforts. Consent. Privacy. Non-abusive relationships with companies generally. That said, I'm worried that most of the regulatory enforcement efforts are focused on technicalities without reference to real world achievements.
Consent is regulated under the GDPR and the majority of consent banners/popups you see today are not compliant. For example, the regulation explicitly mandates that pre-ticked checkboxes are not compliant and that it must be as easy to accept than to decline.
According to the article, this fine is for a breach of the ePrivacy rules (which is the earlier - and somewhat stupid - "cookie law") which exclusively cares about cookies as opposed to the broader goal of the GDPR. On the plus side, enforcement of ePrivacy might suggest that we'll see enforcement of the GDPR too, and that's great news.
Either way though, the concept of consent is similar in the GDPR. It is notable that GDPR makes more effort to define consent better, and implicitly deals with the fact that choice and such are important.
How that translates into enforcement/compliance... I guess we'll see. I think we both agree that none of these recent legislative changes (also in the US and elsewhere) have given us much improvement on consent, so far. You just might be more optimistic than me on prospects.
I think the problem is a hard one, at least within our current normative frames. A regulator has very few nearby examples to draw on, for an enforceable model of consent. They need a binary, but a broader concept of consent isn't very amenable to that.
For example, the recent clarification said:
"The GDPR does not allow controllers to offer pre-ticked boxes or opt-out constructions that require an intervention from the data subject to prevent agreement (for example ‘opt-out boxes’)."
But of course that applies to PII, not all cookies, and so if you have generic analytics cookies that do not result in PII then this does not apply. I think.
https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_gui...
But, it does give internal employees the tools to fix it in smaller companies, or smaller companies that use the services of these global companies(ex, google analytics).
Pre-gdpr, if I raised some of these points in any of my workplaces, nothing ever came out of it. Now, it's a different story.
Same with direct-marketing spam e-mails, where a customer complains.
It'll take some time for regulators to sort out the big offenders, but the regulation is already having a positive effect within smaller companies.
From experience, a lot of folks were waiting to see what Google/Amazon/FB/etc were doing and using them as examples of what to do. These fines should help apply some downward pressure now that the regulator has explicitly called out this illegal behaviour.
My greater reason for "scoring" progress on consent as "no real gains" is less about "compliance" and more about the goals of this compliance. What does consent mean to a non-lawyer and would do we want legislators/regulators to pursue it in the first place?
The model of consent being litigated here doesn't, imo, lead to noticeably more choice or dominion vis a vis companies. It just leads to technicalities about how popups need to be designed. Form rather than substance.
I think the reason these laws have been more effective on disclosure is that the legible, lawyerly definition of disclosure is the same as the common sense one. Consent... not so much. The actual point is not whether or not a document was correctly initialed on page 6.
The clusterfuck comes from every single ad-based business toeing the line in a giant tug of war between PR, legal & revenue.
If google had simply written : " Hey, we have a tracker on almost every website in the world, which we will use to monitor all your browsing habits and share with [this list of 100 other business]. This tracking pay for the app you are about to use. [Continue Tracking] [No thanks] "
They would be fine (legally, not financially), instead they use some king of weird pop-up with no meaning, and they now have to pay the price.
Sad world we live in if that's true.
1: https://en.wikipedia.org/wiki/P3P
2: https://en.wikipedia.org/wiki/Do_Not_Track
3: https://arstechnica.com/tech-policy/2020/10/coming-to-a-brow...
Pairing one of these standard with laws would be a powerful solution with good UX.
But you are right. It isn't ideal.
The DNT (Do Not Track) header was far too simplistic, and completely unrealistic.
I'm imagining having to specify a purpose when creating cookies, such as "session cookie", "advertising", "tracking", and then dealing with consent using a consistent, built-in browser mechanism.
Would be really interesting to flesh out this idea and get feedback, in the unlikely case that it hasn't been done before...
In the USA, corporations basically own the Democratic and Republican parties, at least the leadership. Fat chance of this happening here.
Is there a browser that pretends to accepts all cookies but never saves them?
So to be able to somehow reduce the exposure, while avoiding every time clicking for a long time to accept and reject all the conditions from some big sources like Google (where in Google case is anyway not possible to affect much in spite of what one clicks, as the EU sees), one way would be to construct the compartments, i.e. keep a few "related" sites inside of something that the sites see as a unique browser. Then one has to maintain as easy as possible all that, to appear to the sites as "unique browsers", while using one.
Firefox has the "containers" for that but the use of them is, as far as I've tried, a bit clumsy -- it's still quite hard to manage what happens in which container -- there's too much manual work to do and it's easy to make errors, even if the user has the general idea of how he'd like to compartmentalize his surfing.
Chrome, of course, is less interested to enable their users to hide something from Google.
And Firefox is also not guaranteed to ultimately do exactly what the user would like the most, especially as the users for years flocked to Chrome, directly showing that they "don't care" giving Google what Google wants, as long as it's more "convenient." The structure of Mozilla entities is also somehow made to induce some decision problems which became more prominent with the time.
It doesn't seem that the "free market" can solve this, and EU intervening long-term could work, if they manage to be consistent enough and manage to enforce that. But it takes a lot of time.
I use the Temporary Containers extension in Firefox, and I think that comes pretty close. Every tab can hive its own cookies, separate from all other tabs, which disappear when the tab is closed.
I've got mine setup to delete cookies for a domain when the last tab for that domain is closed. I also run Ublock Origin, don't accept third party cookies, and have javascript turned off for all domains by default.
Combined with blocking all third party cookies, this seems to be pretty good.
Obviously, the issue is now that Google now prompts you almost every time you visit.
Firefox has some extensions for fine grained rules on cookies. After you get annoyed by things breaking because cookies don't live for long enough, you can install one and set a different lifetime for the ones you want.
Yes, it's about user protection because it was unclear that a popup was gathering consent to be tracked, and impossible to refuse to give it.
What more proof do you need that this is for users? Do you think the French government has to beg for its budget from private companies?
Edit: this should be opt-in really, as tracking is explicitly stated as a consensual activity.
Storing a cookie that says the the user opted out of tracking is perfectly fine.
GDPR isn't about cookies. It's about tracking of personal information.
The ePrivacy Directive (which is called the "EU Cookie Law," the same way that the ACA is called "Obamacare") covers reading or writing data from a user's terminal device. That will include cookie-equivalents like local storage. In fact, because it covers "reading" separate from "writing," it also includes reading browser settings like user-agent string or location/language headers, and 99% of fingerprinting techniques.
Cookies require consent unless they are essential to the service that was requested by the user. The canonical example is using a cookie to manage a user's shopping cart on an ecommerce site. Shopping is what the user has requested to do, a cookie (or moral equivalent) is basically necessary to do that, no consent required.
By extension, denying cookies is a positive action taken by the user directing the site to alter its behavior. If a cookie is needed to perform that task, it's allowed even if cookie consent has otherwise been denied.
If they really wanted to make cookies completely optional then they should have pushed the responsibility onto browsers. At least then we'd have a consistent interface rather than some javascript which pops up 10 seconds after the page has loaded.
Of course it takes into account the finality of the cookie (or any tracker for that matter).
[1] https://www.cnil.fr/sites/default/files/atoms/files/draft_re...
Meanwhile, advertisers value users' data like gold. Unlike server time, most advertisers are okay to collect their own data for advertising purposes, and this causes them to have an unwritten agreement to collect data. Unless there is a stronger stick to force them otherwise, it is in their best interests to collect data and you need to have active intervention to prevent it.
On the other hand, if you follow the limits in DNT, you get nothing, and the consequences of not doing so are ... nothing, so companies did not follow that. (See also P3P for another previous attempt)
DNT has no mutual benefit, the benefit is only to the end-user asking not to be tracked. The benefit is also not immediate, it's somewhere down the road. Ignoring robots.txt can immediately cause problems for both the client and server.
X-Consent: no-cookies
X-Consent: cookies-ok
Sites would have gobbled that header up overnight, and the other browsers would have received substantial pressure to follow.But it's a missed beat by now, nobody is paying to have hundreds of thousands of web sites updated for such a thing even if it did exist.
Sucks none of the major browser vendors are based in Europe or this might have happened. Meanwhile, I'm no lawyer, it's not clear whether the header would pass the legal test, but I'm sure a sufficiently motivated party might have a good shot at arguing that it did
The do not track header is about 10 years old, ans was promptly ignored by all websites
DNT: 1
DNT: 0For every domain that wants to create cookies, I should be prompted by the browser (like I allow camera access) if I authorize it to do so, we can even imagine that each domain would have cookies purpose information ('mydomain.com/cookies_policy') in JSON that the browser is able to present to the user (describing each cookie of the domain). Then the browser would be responsible to never create cookies that I rejected.
The main advantage would be that in incognito mode I would not have to repeat myself 10 times a day.
Behing all the legalese and marketing-speach, all the other purposes boils down to :
- We are too lazy to setup a matomo, so we are giving google your browsing pattern.
- FB is forcing us, so we can pay ever so slightly less for ads
- Google is offering to tell us your sex and age
- If we dont track you, we will show you a viagra ad.
- Through 4 intermediaries, we can pay this totaly-objective-blog which sent you here.
I'd love to hear from someone with a complex cookie consent pop-up, but i'd bet there is about 80% "accept all" (because the users have been trained to do it) 19% "reject all", and no-one is mixed.So the do-not-track would have been accurate enough.
e.g: Tying together two browsing sessions by one user on two different devices.
I do not want to disable all cookies, I'm perfectly happy to use credential cookies or a shopping cart, I do not want to disable everything indiscriminately.
Also I shouldn't have to out out.
The cookie banner that you have to refuse/accept only concerns cookies that are not necessary for the proper functioning of the site. So login cookies or shopping cart are unaffected by the consent, and if your site has nothing else than this, it does not need to ask for consent.
That's why GDPR is so powerful and a well thought out regulation. Replace the technology completely, but GDPR still applies as user-unique identifiers are still used. ex, cookie with fingerprint.js, nothing really changes. You still need to ask for consent for user-level tracking.
Actually, the law says the tracking cookies have to be opt in, which is why the pop ups are so aggressive and undismissable in the first place.
If I visit a website like say, Instagram, they shouldn't leave any tracking before I've had a chance to read the privacy agreement, decide it's not for me and navigate away.
Sadly, that's exactly what they do and it's about time they were made to follow the GDPR, at least within the EU.
But yes the popups suck. And of course there's an interest in ad companies of making the popups as obnoxious as possible.
The fines aren't large enough. Google Analytics is on 50% of all web content (I should research the actual figure). The fine should reflect the effect that has on Goog's revenue, rather than this pocket-money sum.
European laws doesn't care what way it is done.
It doesn't need to be cookies, it could be actual magic for that matter and EU would still fine them if they use it to collect user data without consent.
And, as others have pointed out: login cookies seems to be fine (as long as one doesn't use them to collect data.)
While scammers rip folks off for huge amounts each year (Microsoft technical support scams etc) regulators are busy with this.
I just wish there was a button that said I accept all cookies and I’d never see these damn pop ups again.
I believe that the way most people who care about this issue have them enabled, but deleted when the browser is closed. Therefore nothing breaks while your browser is opened, and if you restart it, you basically get a fresh start (signed off everywhere).