I do not want to disable all cookies, I'm perfectly happy to use credential cookies or a shopping cart, I do not want to disable everything indiscriminately.
Also I shouldn't have to out out.
The cookie banner that you have to refuse/accept only concerns cookies that are not necessary for the proper functioning of the site. So login cookies or shopping cart are unaffected by the consent, and if your site has nothing else than this, it does not need to ask for consent.
Actually, the law says the tracking cookies have to be opt in, which is why the pop ups are so aggressive and undismissable in the first place.
That's why GDPR is so powerful and a well thought out regulation. Replace the technology completely, but GDPR still applies as user-unique identifiers are still used. ex, cookie with fingerprint.js, nothing really changes. You still need to ask for consent for user-level tracking.
DNT has no mutual benefit, the benefit is only to the end-user asking not to be tracked. The benefit is also not immediate, it's somewhere down the road. Ignoring robots.txt can immediately cause problems for both the client and server.
Meanwhile, advertisers value users' data like gold. Unlike server time, most advertisers are okay to collect their own data for advertising purposes, and this causes them to have an unwritten agreement to collect data. Unless there is a stronger stick to force them otherwise, it is in their best interests to collect data and you need to have active intervention to prevent it.
On the other hand, if you follow the limits in DNT, you get nothing, and the consequences of not doing so are ... nothing, so companies did not follow that. (See also P3P for another previous attempt)
X-Consent: no-cookies
X-Consent: cookies-ok
Sites would have gobbled that header up overnight, and the other browsers would have received substantial pressure to follow.But it's a missed beat by now, nobody is paying to have hundreds of thousands of web sites updated for such a thing even if it did exist.
Sucks none of the major browser vendors are based in Europe or this might have happened. Meanwhile, I'm no lawyer, it's not clear whether the header would pass the legal test, but I'm sure a sufficiently motivated party might have a good shot at arguing that it did
The do not track header is about 10 years old, ans was promptly ignored by all websites
DNT: 1
DNT: 0For every domain that wants to create cookies, I should be prompted by the browser (like I allow camera access) if I authorize it to do so, we can even imagine that each domain would have cookies purpose information ('mydomain.com/cookies_policy') in JSON that the browser is able to present to the user (describing each cookie of the domain). Then the browser would be responsible to never create cookies that I rejected.
The main advantage would be that in incognito mode I would not have to repeat myself 10 times a day.
Behing all the legalese and marketing-speach, all the other purposes boils down to :
- We are too lazy to setup a matomo, so we are giving google your browsing pattern.
- FB is forcing us, so we can pay ever so slightly less for ads
- Google is offering to tell us your sex and age
- If we dont track you, we will show you a viagra ad.
- Through 4 intermediaries, we can pay this totaly-objective-blog which sent you here.
I'd love to hear from someone with a complex cookie consent pop-up, but i'd bet there is about 80% "accept all" (because the users have been trained to do it) 19% "reject all", and no-one is mixed.So the do-not-track would have been accurate enough.
e.g: Tying together two browsing sessions by one user on two different devices.