If they're asking about cookies for GDPR then that's a mistake on the part of those sites. You can read about the details of PECR here https://ico.org.uk/for-organisations/guide-to-pecr/what-are-...
Of course under GDPR they may need to get permission for other forms of data processing (signing you up to a marketing mailing list, for example), but the rash of cookie permissions banners are because of PECR and similar legislation in other EU countries.
It’s getting more and more difficult to have a good experience browsing the web. That worries me.
For advertising and behavioural tracking cookies, consent is required if it's tracking your personal data to the level of individually identifiable people, but frankly they shouldn't be doing that.
I've personally implemented websites in the EU with logging in, carts and analytical tracking that didn't require up-front consent popups because their behaviour was already reasonable and therefore compliant.
Some of us believe that the bigger sites deliberately use obnoxious consent forms in order to encourage USA residents to remain politically in favour of "implied consent" to individual behaviour tracking. In other words, obnoxious on purpose to give the impression the EU system is more onerous to each user than it really has to be.
After the UK leaves the EU I will do my browsing via a VPN through an EU country specifically because I want to be able to deny all such consents except to sites that I trust and support. (In practice I grant consent to about 10% of sites and deny the other 90%).
If I can find a browser extension to automate denying consent that would be great, but if I can't then I'll do it manually.
The thought of my consent to being tracked down to the level of individual, personal detailed behaviour being "implied consent" the USA way is horrible. I do not consent, full stop. It seems an affront to basic legal principles that the norm is for people to not be told about or therefore have the opportunity for informed consent to the detailed databases built up about their every action online, similar to credit files but much more detailed and secretive.
But anything automatic can have serious downsides, what happens if you start denying ‘good’ sites without realising it. Should all things that require consent be blocked?
This World Wide Web of permissions sounds like it’s going to be a bit of a nightmare.
Just like the iOS/new Android permissions Dialogs. No to all by default, only allowing specific permissions on demand.
Compare that to reading a magazine:
- Step 1 - open
- Step 2 - read
It’s night and day. Eventually it will be too difficult to use the web. I’m think people who make a living from building for the web have not grasped the severity of the problem.
If you worked in the movie business and someone said that eventually it would be too difficult to watch a movie, because you would have to give permission left right and centre, you would be worried because that’s bad for business. Your viewers will eventuakly go do something else.
Well that’s what’s happening on the web.
And one is not obliged to agree for using the service.
Of course, US FAANG companies try to create a kind of backlash, also things like when Amazon tries to force users to use credit card payments when other payment methods like bank transfer in advance work fine. But on the other hand, there is a noticeable increase in web shops in the EU which, for example, do not require any account creation at all - put something into the shopping cart, go to check-out, enter your address, enter your SEPA direct debit number, done. It is much faster and serves me as a customer better.
And no GDPR consent form needed, as all the processing is only for what is needed to do the payment and the delivery.
[RANT] They should never have been implemented that way IMHO -- a different API or IETF-ish agreed HTML meta tag that would inform the browser of the scope, entities etc. would have allowed the browser to offer overall policy choices to the user.
Most would be "I don't care, do whatever you want to me" but those who do care could have been picky. That would also have allowed the browser to generate reports for the user regarding which sites currently have which permissions, etc. This would have put the onus on the browser implementation to get it right, and not e.g. fail to show the messages, but one could argue that any browser could get the random CSS used for these prompts wrong and not show the message.
I'm a GDPR fan and will likely use this jurisdiction transfer as a ceremonial point to close my FB account for good.
Some companies want to use the web to try to change users behaviour, and many users want those companies to change their behaviour. That’s not a solvable problem, it’s a circular reference bug.
So maybe better tools might actually make it worse, in a race to the bottom sort of situation.
My main concern is that the consent forms, however well meaning they might be, are creating a horrible environment. There are lots of perverse incentives for people to ruin the web experience. Some players stand to gain a lot from a horrible web environment. For example ones that have competing information products.
I’m increasingly thinking it would be better to just not have consent forms, and with better browser tools, people would hopefully go to websites that treated them well.
And just by looking at Google, they are doing that in an increasingly aggressive way.
That would not have been used.
The whole reason why all the consent forms are constantly violating the GDPR is because companies want to make it as hard as possible to say no.
They'd only accept the browser API if the "No to all" button (which by law has to be default, has to be the option chosen if you click anything except yes, and has to be easier to use than "Yes to all") was hidden behind 3 layers of "are you sure", each of which having a 30 second timer before you could continue.
That's the whole reason this consent form disaster exists: because companies are trying to do everything they can go get around the laws.
Just look at the Do Not Track header: it's a legally meaningful statement that companies should follow. They don't.
The EU basically looked at that situation with a competitive browser market, extensions, the existence of the same feature in the past and said, "screw all that, the Commission knows best". Which is exactly the attitude that drove people to vote leave in the first place.