Now you know which websites are willing to absolutely ruin your experience just to abuse you. The implications can be seen pretty much everywhere in society, it is a momentous step in the right direction.
Not saying the legislation couldn't be improved, though.
I think what happened when brexit went into full effect was pretty telling. Both Facebook and Google were on their toes to get back to abusing the data of UK citizens. There's much to be gained.
https://www.theguardian.com/technology/2020/dec/15/facebook-...
https://www.reuters.com/article/us-google-privacy-eu-exclusi...
But damn, that is indeed a pretty good indicator that it’s working as intended.
Which is absolutely all of them. I guess the legislators wanted the popups to be annoying so publishers would be forced not to import their party scripts. Turns out publishers can’t stay open without the ads that pay their bills which means popups are the new normal, to the point where when I see a website that doesn’t have popups I suppose they are just in violation of the law. Thanks EU!
Nope, GDPR is pretty clear on this point. All they want is informed consent. GDPR doesn’t care how you get it.
Who wants the pop-ups to be annoying and riddled with dark patterns are the ones implementing it, exactly to cause this kind of reaction on you so you start hating the law, not the ones who are trying their best to skirt around it, to find the loopholes and abuse them. To make your experience as poor as possible while being compliant so you will focus your hatred on the ones who wrote the laws.
This is part of their game, make the experience miserable to people start getting angry at politicians.
Don't fall for that.
This is the point: the legislators were exceedingly naive, and created a bad outcome.
'National Geographic' is not evil, they are struggling and most of these sites are not giant entities with well-staffed experts.
It's a good example of poorly designed legislation.
"This is part of their game, make the experience miserable to people start getting angry at politicians."
This is completely false and conspiratorial, almost disturbingly so.
These are normal companies, with normal people, pragmatic policies.
The legislation has unconditionally failed at least in this specific way - all we have now are constant popups. That's the reality of the change.
- The default option of consent is opt-out.
- Opt-in and opt-out should be equally easy and accessible.
Tell me how a company who would be trying to be ethical and follow this spirit would come up with the current pop-ups.
Don't blame the legislation for allowing dark patterns to be used due to loopholes or failure of prediction all possible clever tricks to circumvent the spirit described above.
It hasn't unconditionally failed, the pop-ups are still there and I opt-out of every single one of them.
Except one: schneidersladen.de - they follow exactly the spirit of the law, I put the bar there.
There's a very simple solution: respect my privacy and don't store or sell data about me. If you only use cookies necessary for running the site, then you don't need to do anything.
If you must track me, then do as sibling commenter said. If you store privacy-invading data about me, then you damn well better know the laws and if you don't, then sorry, you can't track me on your website.
The business model of the internet is advertising, as of today, that requires cookies, which by the way, don't represent material harm.
Also - you're specific view is in no way representative of the population at large. 'Most people' would rather remain completely private at the same time, they would forgo at least some degree of privacy for the option.
Given the choice of a:
a) No content b) Constant popups c) The previous imperfect norm but where people can get their content without hassle ...
They would chose option 'c' - hands down.
The effect of legislation is to create popup hassles for individuals that they never read - and to provide no real material improvement for people.
What they could have don instead.
i) Orchestrated cookie-free advertising exchanges and solutions
ii) Created privacy 'categories' and relevant rules and symbols, like movie ratings - and a symbol could be placed o prominently on the site so consumers have a quick and easy mechanism to know where they stand.
iii) worked with other nations and groups to arrive at consistent standards. With Canada, Australia, Japan on board, it might be very well possible to convince a Biden-lend USA to buy into some kind of standard.
What we have now is not pragmatic and it's ill conceived.
This would all go away if users were will to fork over 5 cents to read an article.
For the big players it is easy. They often don't annoy you with consent banners because:
- they have legal departments that understand GDPR and protect them (e.g. GitHub)
- they require your login and therefore have your consent anyway (e.g. Facebook)
- they can afford to skip Cookies because they have elaborate fingerprinting solutions
- they just ignore the law and risk be sued (e.g. Germany's Spiegel Online)
This is really just a special case of your last point. As far as I know, there is nothing cookie specific in the GDPR.
This directive defines in (24) [1] : So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users.
The definition is broad. Does server-side fingerprinting solutions fits into it? Maybe not in the letter of the law, but at least in the spirit. Until a court decide either way, we won't know for sure.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
There is a ton of literature about how it should be done, there has been enough press for anyone to be aware that it's a serious subject that needs to be studied, and small companies will often consult with external legal advisors because they can't afford to get on the wrong side of the law on this aspect.
I've participated to a ton of these discussions in small and big entities, basically everytime a new service is launched or significantly changed.
In my opinion it's pretty close to handling your finances: you don't go through all the hoops to pass you holiday rental as expenses just because you didn't know better.
Conversely, some can't afford to get on the right side of the law on this aspect. In our case, we had ~15 customers in the EU (out of ~2000), totaling $2,000/mo MRR. After talking with our legal counsel, we decided to exit the EU market entirely. Our business model was a simple niche B2B SaaS. We never sold, shared, or traded any data of any kind.
When we fired our EU customers, they were very upset! They assumed we were doing something "shady", which wasn't the case at all. The regulatory burden simply wasn't worth the relatively small MRR. The quotes provided for a third-party DPO was higher than our revenue in the market, and the only other option was for me (an overworked founder) to take on that role, and I valued my time higher than that MRR.
Those customers lost out, because after we exited, so did every other player in our niche. Nobody wanted to deal with it.
P.S.: no opportunity is lost. There is always someone else who seizes it. :)
I'm sure these corporations want a random person in HN to provide service to 12 customers?
It's false to suggest that material barriers to providing services are only contextually relevant. It's a permanent tax and it's real.
Edit: Also if you are not selling/using this data, why can't you remove everything but session cookies? Please note I'm not a web developer so the answer can just be because it's too much work.
I would argue that the duties of a DPO is not more work than a small company could handle and indeed, it's slightly odd to me that a small company would think that a small handful of data erasure requests or subject access requests are a) somehow difficult to do given 30 days notice and b) somehow consume more time than the profit left over on $24k revenue buys?
Most companies here in the UK just take it in their stride and have no problems complying.
At the time, being that the DPO role was new we didn’t know how many requests to expect. And while the law may allow for 30 days, our customers wouldn’t take it well if it took us longer than a couple days (our customer service SLA was 24 hr first resolution time). Their customers would complain to our customer who in turn would complain to us. If we make our customers look bad, we hear about it loudly and clearly.
To each their own, I suppose. From my perspective as an overworked founder, with a small team, growing at >200%/yr, we didn’t see the need to take on additional work just to maintain a very small revenue stream
I don’t fault companies for wanting to remain in the EU market, but for us, it didn’t make much sense at the time as our real growth opportunity lay in the Us/Canada (mostly due to consumer habits in the region).
I have no issue with the spirit of GDPR, and as a human, I support it personally. But, for my business at that point in time, it didn’t make economic sense to comply, so we left.
Doesn't that make you a data processor rather than a data controller - i.e. not at all your problem for your end user's end users?
Companies relying on information from literature, the press and from external advisors is part of the problem.
All these parties often have motivations that are not necessarily 100% aligned with their clients. In the best case they are just overcautious because they don't enjoy the same protection as lawyers. In the worst case they sell GDPR products or profit indirectly from the sale of these products.
All that most companies need is advice from a lawyer that understands GDPR and acts in their best interest. That alone would kill a good deal of cookie banners.
Funny coincidence that you picked GitHub since pretty much to the day two month ago that they removed all non-essential cookies https://github.blog/2020-12-17-no-cookie-for-you/
No cookie banner is required for session cookies etc.
Requiring you to login doesn't automatically mean consent. In fact, the laws state that you cannot make consent a requirement for using the service. You can do login without needing any consent, as cookies needed for functioning of the site are exempt, but even if it wasn't the case, opting into some doesn't automatically opt you in to all.
> they can afford to skip Cookies because they have elaborate fingerprinting solutions
The law isn't actually about cookies at all and rather about tracking/storing. Things like localstorage are counted the same as cookies. I'd have to check the exact language, but I wouldn't be surprised if fingerprinting isn't against the cookie law too.
I am not dismissing the need to let consumers know how their habits and information are used I am merely stating that many here overreact on behalf of people who really could care less, they just want their content
One issue I do see with GDPR (or its consequences) is that a market participant that only sets those strictly necessary cookies actually now gets viewed by some as iffy, because they don't ask for consent.
Basically, the industry standard of treating users (paying or not) like shit has normalized this sort of abuse/harassment so much that "the good ones" stick out in a bad way.
None of which is meant to discredit GDPR though. If anything, I'm looking forward to more case law like from last year in Germany, where a dark-patterned cookie banner was ruled to be so misleading that it didn't constitute informed consent anymore.
The GDPR is lacking enforcement, if anything.
I block ALL cookies and many of those sites with "strictly functional" cookies still function, which means that those cookies aren't necessary.
It does mean e.g. clicking "°F" every time on a weather site, because you're an American living in Europe. A strictly functional cookie could remember that choice.
An API where advertisers can also store advertising-ids and more site-specific, tracking-related settings into (if the user grants this permission), giving them the possibility to move away from the use of cookies for this purpose. Then it should become obligatory to not use cookies for tracking and ad-related purposes.
There are cases where 3rd-party cookies are important, and I'm a bit afraid that Google wants to remove them altogether.
I personally don't care about non-personalized ads. If the advertisers see that it makes no sense to offer me a random ad, they may start looking at the context of the page where they are serving there ads, in order to serve me a bit more relevant ads. Then again, there are others who absolutely love personalized ads. So this solution would be a fair offering to the advertisement industry.
This API could even be so advertiser-friendly that the user could even specify categories of interest so that the advertiser doesn't have to guess through tracking.
(Disclosure: I work on ads at Google, including the seller-side of Turtledove. Speaking only for myself.)
I'm very happy that I can at least click "say no to all" when I get to a new website. Hopefully if enough people do that, they'll realize that the current approach is counterproductive and switch to a different model eventually.
I don't know if you've ever bothered to go through the list of "third parties" you can now opt-in to track you, but I'm frankly amazed by the sheer number of them. Literally hundreds. Before the GDPR I knew that I was tracked online, but honestly I underestimated the scale of it all. Apparently hundreds of companies around the world used to track my every step online. Good riddance.
I think it may be better to have this as a decision the user chooses once within their browser, and the browser can then pass along the intention to the website. There can maybe also be a third option where the user could then choose on each site, and the browser would show the choices, rather than the website itself. This would standardize the UX around the issue.
I agree it'd be better handled by the browser than each website, though.
Unfortunately, many websites that I’ve seen have only “customize” and “accept all”. And the customize pane then contains dozens of preselected checkboxes (which, AFAIK, isn’t allowed, but I digress). Each checkbox is for a separate tracker I need to disable before clicking “save”.
The problem is absolutely the lack of enforcement.[a] If it was being enforced better, these sites would be fined until they fix themselves.
[a]: Yes, I’m aware that it is being enforced. I’m complaining that it’s not enough.
Sure some people will click accept but some of them will know who is the actual bad guy that sends their data to 100+ third parties and what websites are respecting them or at least respect the laws.
I agree that browsers could do a better job, maybe implement a shit list, put all shitty websites there and ask you only once if you want to accept to allow this bastards to track and sell your data or if you want to open the website in a special container. Then if you decide to use the container the browsers should try to do their best to limit the tracking, maybe by blocking requests to the trackers, clearing caches often, disabling some features that could fingerprint you and if it works just disable JS.
But who knows, maybe we will have to pass laws to force the popups to use certain fonts, colors and input types because the majority of websites are evil.
And why is that button allowed to be the "Accept Everything" button? There should be two buttons, equally easy to find and press.
The law doesn’t require this, it only requires informed consent.
> I think it may be better to have this as a decision the user chooses once within their browser, and the browser can then pass along the intention to the website. There can maybe also be a third option
This is would be an allowable approach under GDPR. Someone just needs to build it and make it happen. Unfortunately the “do-not-track” debacle shows that ad companies aren’t interested in playing ball. Hence our current mess.
What does a non-annoying prompt look like?
Instagram has the most annoying one ever, if I stumble upon it by accident I am so annoyed that I need to count to 10. And I am not even using it, its just random click
The far less annoying popups are barely noticeable and do not block/fade content or have missing options like "NO, I don't want cookies, let me in".
Sites win because exercising your privacy rights even under the GDPR is an inherently annoying thing to do.
Under GDPR:
- only cookies and data strictly required for the site's functionality don't require consent
- collection of any other data requires consent
- pre-ticked boxes, lack of "reject all" button, leading the user to click "allow all" and similar dark patterns are not consent, and are, strictly speaking, violating the law.
See? exercising your privacy rights under the GDPR should be extremely easy. Too bad the law isn't enforced vigorously enough.
It was simply designed to make it easier to exercise your right to privacy, by forcing companies (and by extension their websites) to get informed consent before they invade your privacy.
There’s many reasons why we’re in our current mess, but I don’t think making companies get informed consent is “tech-hostile”. It’s privacy invading hostile, and if privacy invasions are now synonymous with the tech-industry, then as an industry we need to take a long hard look in the mirror and decide if we’re going to continue enabling this behaviour, or find other business models that don’t rely on trampling the rights of the ignorant or uninformed.
I honestly don’t understand why people take such an issue with the concept of informed consent. It’s one the foundations of a free and equal society.
If it were as hard to opt-in as it is to fully opt-out, or as easy to accidentally (and permanently) opt-out as it is to accidentally (and permanently) opt-in, then there might be a case for something other than the sites and/or their partners being the problem.
The legislation does not in any way force sites or their partners to make your browsing so inconvenient if you don't want to just click "accept all from all without or without lube". They could implement a small non-modal active-opt-in option, they instead chose to implement labyrinthine modal hunt-the-231st-opt-out adventure games.
To do that, of course, the website would need stop sending your latest ip address, your unique identifier, and the information that you’re a techie interested in Tiktok to all ad agencies and data brokers.
Also what if big companies want to make your experience as poor as possible in order to make you think that this law sucks?
Maybe using private mode in browser is making your experience even worse?
I actually find myself digging into the settings that are offered to click on "Reject All" where possible. I wish my region had the same data protections :-/
The root cause of your experience being worse is not the legislation, it's that the site doesn't follow the intent/purpose of the law. They want to annoy you until you click "yes".
They could simply present you with a yes/no modal once and be done with it, but they choose not to, hoping that they will break you down with time.
Any extra modal, as simple as it might be, leads to a really bad user experience and wasted time.
If invading your users' privacy is more important than your site's user experience, then the blame is on you, not the legislation.
This applies to all laws that are passed. It is a frequent criticism and problem, of laws, is that there are often unintended consequences. And that is the fault of the law, that they did not consider the unintended consequences.
What they should have done is made a public tool that checks your website and says: yes this site is GDPR compliant or no, it is not because A,B,C.
[0]: https://addons.mozilla.org/en-US/firefox/addon/sticky-ducky/
[1]: https://github.com/ryanbr/fanboy-adblock/blob/master/fanboy-...
https://ec.europa.eu/digital-single-market/en/proposal-epriv...
Sounds very ominous, don't law enforcement agencies have access to the "traditional telecoms operators" data?
On topic, a Do-Not-Track header setting that automatically opts-out of everything and the new "legitimate interest" trend, would be awesome.
There are a number of ways I can get to that content.
However, I don't think the content is worth it.
I've found a very strong correlation between low-quality content and low-quality presentation.
When I see a site which pulls this kind of crap or requires several megs worth of JS just to display text, I just assume it's low-quality content and move on.
Sometimes there are exceptions, but they're rare.
And sites can still provide ads. Google still provides ads to me with customizations turned off.
So yeah, I'm pretty bothered by them as well but I know where the blame lies
Yeah, and women's suffrage caused longer lines at the polls because more people vote so you would have to wait longer. It's not about the experience, it's about your rights.
Please also remember that the GDPR is also applicable outside the internet, and protects people from IRL data gathering.
Dark patterns, web wide tracking, anti-consumer features. vendor lock-in, you name it are all over the place and common practice and not there to help/protect consumers.
Personally I feel the problem arose from trying to write extremely generalist legislation in the GDPR without actually addressing the economic incentives OR mandating a technical solution.
Mandating a technical solution such as "respect the DNT header" would have the disadvantage of limiting innovation, but would have forced a clear division of websites into "you can't browse here without turning DNT off" and ones that actually worked properly.
Alternatively, just straight up banning the browser-targeted advertising practice would take away the economic incentive to do this kind of nonsense. That would force the "how do we get paid" question again, which remains awkward.