Now you know which websites are willing to absolutely ruin your experience just to abuse you. The implications can be seen pretty much everywhere in society, it is a momentous step in the right direction.
Now you know which websites are willing to absolutely ruin your experience just to abuse you. The implications can be seen pretty much everywhere in society, it is a momentous step in the right direction.
Not saying the legislation couldn't be improved, though.
I think what happened when brexit went into full effect was pretty telling. Both Facebook and Google were on their toes to get back to abusing the data of UK citizens. There's much to be gained.
https://www.theguardian.com/technology/2020/dec/15/facebook-...
https://www.reuters.com/article/us-google-privacy-eu-exclusi...
But damn, that is indeed a pretty good indicator that it’s working as intended.
An API where advertisers can also store advertising-ids and more site-specific, tracking-related settings into (if the user grants this permission), giving them the possibility to move away from the use of cookies for this purpose. Then it should become obligatory to not use cookies for tracking and ad-related purposes.
There are cases where 3rd-party cookies are important, and I'm a bit afraid that Google wants to remove them altogether.
I personally don't care about non-personalized ads. If the advertisers see that it makes no sense to offer me a random ad, they may start looking at the context of the page where they are serving there ads, in order to serve me a bit more relevant ads. Then again, there are others who absolutely love personalized ads. So this solution would be a fair offering to the advertisement industry.
This API could even be so advertiser-friendly that the user could even specify categories of interest so that the advertiser doesn't have to guess through tracking.
(Disclosure: I work on ads at Google, including the seller-side of Turtledove. Speaking only for myself.)
One issue I do see with GDPR (or its consequences) is that a market participant that only sets those strictly necessary cookies actually now gets viewed by some as iffy, because they don't ask for consent.
Basically, the industry standard of treating users (paying or not) like shit has normalized this sort of abuse/harassment so much that "the good ones" stick out in a bad way.
None of which is meant to discredit GDPR though. If anything, I'm looking forward to more case law like from last year in Germany, where a dark-patterned cookie banner was ruled to be so misleading that it didn't constitute informed consent anymore.
The GDPR is lacking enforcement, if anything.
I block ALL cookies and many of those sites with "strictly functional" cookies still function, which means that those cookies aren't necessary.
It does mean e.g. clicking "°F" every time on a weather site, because you're an American living in Europe. A strictly functional cookie could remember that choice.
For the big players it is easy. They often don't annoy you with consent banners because:
- they have legal departments that understand GDPR and protect them (e.g. GitHub)
- they require your login and therefore have your consent anyway (e.g. Facebook)
- they can afford to skip Cookies because they have elaborate fingerprinting solutions
- they just ignore the law and risk be sued (e.g. Germany's Spiegel Online)
There is a ton of literature about how it should be done, there has been enough press for anyone to be aware that it's a serious subject that needs to be studied, and small companies will often consult with external legal advisors because they can't afford to get on the wrong side of the law on this aspect.
I've participated to a ton of these discussions in small and big entities, basically everytime a new service is launched or significantly changed.
In my opinion it's pretty close to handling your finances: you don't go through all the hoops to pass you holiday rental as expenses just because you didn't know better.
Conversely, some can't afford to get on the right side of the law on this aspect. In our case, we had ~15 customers in the EU (out of ~2000), totaling $2,000/mo MRR. After talking with our legal counsel, we decided to exit the EU market entirely. Our business model was a simple niche B2B SaaS. We never sold, shared, or traded any data of any kind.
When we fired our EU customers, they were very upset! They assumed we were doing something "shady", which wasn't the case at all. The regulatory burden simply wasn't worth the relatively small MRR. The quotes provided for a third-party DPO was higher than our revenue in the market, and the only other option was for me (an overworked founder) to take on that role, and I valued my time higher than that MRR.
Those customers lost out, because after we exited, so did every other player in our niche. Nobody wanted to deal with it.
P.S.: no opportunity is lost. There is always someone else who seizes it. :)
I'm sure these corporations want a random person in HN to provide service to 12 customers?
It's false to suggest that material barriers to providing services are only contextually relevant. It's a permanent tax and it's real.
Edit: Also if you are not selling/using this data, why can't you remove everything but session cookies? Please note I'm not a web developer so the answer can just be because it's too much work.
I would argue that the duties of a DPO is not more work than a small company could handle and indeed, it's slightly odd to me that a small company would think that a small handful of data erasure requests or subject access requests are a) somehow difficult to do given 30 days notice and b) somehow consume more time than the profit left over on $24k revenue buys?
Most companies here in the UK just take it in their stride and have no problems complying.
At the time, being that the DPO role was new we didn’t know how many requests to expect. And while the law may allow for 30 days, our customers wouldn’t take it well if it took us longer than a couple days (our customer service SLA was 24 hr first resolution time). Their customers would complain to our customer who in turn would complain to us. If we make our customers look bad, we hear about it loudly and clearly.
To each their own, I suppose. From my perspective as an overworked founder, with a small team, growing at >200%/yr, we didn’t see the need to take on additional work just to maintain a very small revenue stream
I don’t fault companies for wanting to remain in the EU market, but for us, it didn’t make much sense at the time as our real growth opportunity lay in the Us/Canada (mostly due to consumer habits in the region).
I have no issue with the spirit of GDPR, and as a human, I support it personally. But, for my business at that point in time, it didn’t make economic sense to comply, so we left.
Doesn't that make you a data processor rather than a data controller - i.e. not at all your problem for your end user's end users?
Companies relying on information from literature, the press and from external advisors is part of the problem.
All these parties often have motivations that are not necessarily 100% aligned with their clients. In the best case they are just overcautious because they don't enjoy the same protection as lawyers. In the worst case they sell GDPR products or profit indirectly from the sale of these products.
All that most companies need is advice from a lawyer that understands GDPR and acts in their best interest. That alone would kill a good deal of cookie banners.
Requiring you to login doesn't automatically mean consent. In fact, the laws state that you cannot make consent a requirement for using the service. You can do login without needing any consent, as cookies needed for functioning of the site are exempt, but even if it wasn't the case, opting into some doesn't automatically opt you in to all.
> they can afford to skip Cookies because they have elaborate fingerprinting solutions
The law isn't actually about cookies at all and rather about tracking/storing. Things like localstorage are counted the same as cookies. I'd have to check the exact language, but I wouldn't be surprised if fingerprinting isn't against the cookie law too.
Funny coincidence that you picked GitHub since pretty much to the day two month ago that they removed all non-essential cookies https://github.blog/2020-12-17-no-cookie-for-you/
No cookie banner is required for session cookies etc.
This is really just a special case of your last point. As far as I know, there is nothing cookie specific in the GDPR.
This directive defines in (24) [1] : So-called spyware, web bugs, hidden identifiers and other similar devices can enter the user's terminal without their knowledge in order to gain access to information, to store hidden information or to trace the activities of the user and may seriously intrude upon the privacy of these users.
The definition is broad. Does server-side fingerprinting solutions fits into it? Maybe not in the letter of the law, but at least in the spirit. Until a court decide either way, we won't know for sure.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
I am not dismissing the need to let consumers know how their habits and information are used I am merely stating that many here overreact on behalf of people who really could care less, they just want their content
Which is absolutely all of them. I guess the legislators wanted the popups to be annoying so publishers would be forced not to import their party scripts. Turns out publishers can’t stay open without the ads that pay their bills which means popups are the new normal, to the point where when I see a website that doesn’t have popups I suppose they are just in violation of the law. Thanks EU!
Who wants the pop-ups to be annoying and riddled with dark patterns are the ones implementing it, exactly to cause this kind of reaction on you so you start hating the law, not the ones who are trying their best to skirt around it, to find the loopholes and abuse them. To make your experience as poor as possible while being compliant so you will focus your hatred on the ones who wrote the laws.
This is part of their game, make the experience miserable to people start getting angry at politicians.
Don't fall for that.
This is the point: the legislators were exceedingly naive, and created a bad outcome.
'National Geographic' is not evil, they are struggling and most of these sites are not giant entities with well-staffed experts.
It's a good example of poorly designed legislation.
"This is part of their game, make the experience miserable to people start getting angry at politicians."
This is completely false and conspiratorial, almost disturbingly so.
These are normal companies, with normal people, pragmatic policies.
The legislation has unconditionally failed at least in this specific way - all we have now are constant popups. That's the reality of the change.
- The default option of consent is opt-out.
- Opt-in and opt-out should be equally easy and accessible.
Tell me how a company who would be trying to be ethical and follow this spirit would come up with the current pop-ups.
Don't blame the legislation for allowing dark patterns to be used due to loopholes or failure of prediction all possible clever tricks to circumvent the spirit described above.
It hasn't unconditionally failed, the pop-ups are still there and I opt-out of every single one of them.
Except one: schneidersladen.de - they follow exactly the spirit of the law, I put the bar there.
There's a very simple solution: respect my privacy and don't store or sell data about me. If you only use cookies necessary for running the site, then you don't need to do anything.
If you must track me, then do as sibling commenter said. If you store privacy-invading data about me, then you damn well better know the laws and if you don't, then sorry, you can't track me on your website.
The business model of the internet is advertising, as of today, that requires cookies, which by the way, don't represent material harm.
Also - you're specific view is in no way representative of the population at large. 'Most people' would rather remain completely private at the same time, they would forgo at least some degree of privacy for the option.
Given the choice of a:
a) No content b) Constant popups c) The previous imperfect norm but where people can get their content without hassle ...
They would chose option 'c' - hands down.
The effect of legislation is to create popup hassles for individuals that they never read - and to provide no real material improvement for people.
What they could have don instead.
i) Orchestrated cookie-free advertising exchanges and solutions
ii) Created privacy 'categories' and relevant rules and symbols, like movie ratings - and a symbol could be placed o prominently on the site so consumers have a quick and easy mechanism to know where they stand.
iii) worked with other nations and groups to arrive at consistent standards. With Canada, Australia, Japan on board, it might be very well possible to convince a Biden-lend USA to buy into some kind of standard.
What we have now is not pragmatic and it's ill conceived.
This would all go away if users were will to fork over 5 cents to read an article.
Nope, GDPR is pretty clear on this point. All they want is informed consent. GDPR doesn’t care how you get it.