Instead, the appropriate framework is that advertisers do not have a moral right to track users unless the user has consented to it. By having the DoNotTrack header be on by default, it means that a user removing it shows consent to be tracked, where previously its absence could also have indicated that the user was unaware of the header.
But that's not what DoNotTrack was. It was supposed to show specific intent. It wasn't there to change the default.
So by removing the intent, the fragile agreement broke entirely.
If you want to change the default, you need something that can be enforced.
It pretty clearly isn't. It should be but isn't.
> DNT was just reflecting the reality of the situation: user not making a choice indicates they don't want you to steal their data.
Advertisers don't need a header telling them what they should do by default. They can get that information from elsewhere. DNT was going to be a way to opt-out, and some advertisers promised to listen to that. Setting DNT without user action removes the "opt".
Perhaps the header should be made to be easy to apply per domain, so websites can request tracking permissions, but in my opinion the necessity of the header is exactly the point of enabling it by default.
The header is simple: I do not want to be tracked. Do not track me. If you want to track me, ask me to disable the header so I can leave your website.
Honestly, I don't understand why this header wasn't mentioned in the ePrivacy directive the EU passed recently. There's a perfectly good way to communicate intent about tracking options to websites, and it's being blatantly ignored.
Which is what it should have been to begin with: a “do track” header that no sane person would opt in for.
The whole “people consent to everything unless they go out of their way to say otherwise” thing is a farce.
By honoring it they would loose an advantage over all the other ones who don't.
[1]: https://spreadprivacy.com/global-privacy-control-enabled-by-...