I think it may be better to have this as a decision the user chooses once within their browser, and the browser can then pass along the intention to the website. There can maybe also be a third option where the user could then choose on each site, and the browser would show the choices, rather than the website itself. This would standardize the UX around the issue.
I agree it'd be better handled by the browser than each website, though.
Unfortunately, many websites that I’ve seen have only “customize” and “accept all”. And the customize pane then contains dozens of preselected checkboxes (which, AFAIK, isn’t allowed, but I digress). Each checkbox is for a separate tracker I need to disable before clicking “save”.
The problem is absolutely the lack of enforcement.[a] If it was being enforced better, these sites would be fined until they fix themselves.
[a]: Yes, I’m aware that it is being enforced. I’m complaining that it’s not enough.
And why is that button allowed to be the "Accept Everything" button? There should be two buttons, equally easy to find and press.
Sure some people will click accept but some of them will know who is the actual bad guy that sends their data to 100+ third parties and what websites are respecting them or at least respect the laws.
I agree that browsers could do a better job, maybe implement a shit list, put all shitty websites there and ask you only once if you want to accept to allow this bastards to track and sell your data or if you want to open the website in a special container. Then if you decide to use the container the browsers should try to do their best to limit the tracking, maybe by blocking requests to the trackers, clearing caches often, disabling some features that could fingerprint you and if it works just disable JS.
But who knows, maybe we will have to pass laws to force the popups to use certain fonts, colors and input types because the majority of websites are evil.
The law doesn’t require this, it only requires informed consent.
> I think it may be better to have this as a decision the user chooses once within their browser, and the browser can then pass along the intention to the website. There can maybe also be a third option
This is would be an allowable approach under GDPR. Someone just needs to build it and make it happen. Unfortunately the “do-not-track” debacle shows that ad companies aren’t interested in playing ball. Hence our current mess.
What does a non-annoying prompt look like?
Instagram has the most annoying one ever, if I stumble upon it by accident I am so annoyed that I need to count to 10. And I am not even using it, its just random click
The far less annoying popups are barely noticeable and do not block/fade content or have missing options like "NO, I don't want cookies, let me in".
Sites win because exercising your privacy rights even under the GDPR is an inherently annoying thing to do.
Under GDPR:
- only cookies and data strictly required for the site's functionality don't require consent
- collection of any other data requires consent
- pre-ticked boxes, lack of "reject all" button, leading the user to click "allow all" and similar dark patterns are not consent, and are, strictly speaking, violating the law.
See? exercising your privacy rights under the GDPR should be extremely easy. Too bad the law isn't enforced vigorously enough.