The tracking request you see above requires informed consent under GDPR, and GitHub does not ask for consent before collecting browsing and device data that is tied to GitHub usernames.
The tracking request you see above requires informed consent under GDPR, and GitHub does not ask for consent before collecting browsing and device data that is tied to GitHub usernames.
the law is simple to break and appear as if you're not. they're a big company and will have this covered if needed
the bottom line is, do you place more trust in your local lawmakers and the website you are visiting than you do in yourself
That's not how informed consent works, you can't just mention the collection of personal data in a privacy policy. Consent must be explicitly requested for this type of tracking, and you must be able to reject it, and continue using the service.
> the bottom line is, do you place more trust in your local lawmakers and the website you are visiting than you do in yourself
The request can be blocked with uBlock Origin, but it's still important to draw attention to tracking that may be illegal, since not everyone has a content blocker installed.
you'll need a stronger arsenal than a content blocker to avoid modern fingerprinting, legal or otherwise
This article may help you understand what consent means under GDPR: https://www.privacypolicies.com/blog/gdpr-consent-examples/#...
from my understanding of the rules even a lot of the informed consent popups today aren't compliant.
If I understand it correctly (and I think I am) the standard is that it should be equally easy to op out as to opt in, and the default should be opt out.
IMO this means I should just be able to dismiss any GDPR compliant box and the result should be no tracking.
also, to contradict your own tangential claim (from your non-authoritative link): "You _should_ ask for consent where you are offering a genuine choice over a non-essential service. Typical examples include:
-Using tracking/advertising cookies"
this document may help you understand the difference between should and must: https://www.ietf.org/rfc/rfc2119.txt
And there is no room for ambiguity in the actual law:
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%...
> Consent should be given by a clear affirmative act establishing a freely given, specific, informed and unambiguous indication of the data subject's agreement to the processing of personal data relating to him or her, such as by a written statement, including by electronic means, or an oral statement. This could include ticking a box when visiting an internet website, choosing technical settings for information society services or another statement or conduct which clearly indicates in this context the data subject's acceptance of the proposed processing of his or her personal data. Silence, pre-ticked boxes or inactivity should not therefore constitute consent. Consent should cover all processing activities carried out for the same purpose or purposes. When the processing has multiple purposes, consent should be given for all of them. If the data subject's consent is to be given following a request by electronic means, the request must be clear, concise and not unnecessarily disruptive to the use of the service for which it is provided.
of course not, it was an example to demonstrate the difference and easier to include one link for both definitions than e.g. two for each from a dictionary
> Never mind the difference between "should" and "must"
given the context I believe the difference is of paramount importance
> do you understand the difference between an RFC and the law?
slightly reworded first question but yes, I do, thanks
> And there is no room for ambiguity in the actual law: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=uriserv%...
that seems a good example for a better source which actually bolsters my point on bad sources, but alas, it's irrelevant. note that it refers to personal data and not (third time lucky) the original argument concerning tracking consent. in fact, I cannot even find any personal data in the OP's URL, probably because no personal data is required to create a GitHub account. let's just ignore that one for now
Not being able to get implicit consent by hiding some terms in a long legal document is the entire fucking point of the GDPR.
Consent is a voluntary action. Usage itself is a form of consent. However a user disagreeing with what the company requires to provide that service but still being entitled to and actively using that service is not workable. User can decide to stop using a service entirely though, if they don't agree with the requirements.
That's meaningless. Usage is already a form of consent. The discrepancy is between the user and the company in what is consented. Forcing the company to provide service to the user even if the user disagrees with an upfront description of what the company requires to provide that service is a completely valid objection.
Also GDPR applies to any organization providing to citizens of the EU, not companies operating there, but that's yet another example of poor design which results in GDPR having little enforcement.
nobody because they are pretty much meaningless in the EU
we got laws to protect consumers, not laws for businesses to trick users into making some meaningless gesture
> the bottom line is, do you place more trust in your local lawmakers and the website you are visiting than you do in yourself
what do you mean by "local lawmakers"? these laws are EU-wide. or did you mean "local" to mean, "non-US"
anyway, these lawmakers are fighting the shitty corporations that pull this tracking stuff
and your bottom line is not really a choice one way or the other. I can use blockers and other plugins to protect myself, AND cheer on the people fighting the fuckfaces that think it's in any way honourable to make a profit by merely following the letter of our laws
but we got some really good consumer protections in the EU. and we try to keep it that way. we're not going to simply roll over because some US corporations are used to being able to track the hell out of US customers