Dutch cookie law may lead to online exodus
ft.com
ft.com
On a side note, not in the article, the same Telecomunications Law also includes articles on net neutrality and by law prevents providers from blocking services. Should make the Netherlands second after Chili to make such a law.
Heck, you could even write that as a separate provision (e.g. "In order to sign you in, we'll need to store a cookie in your browser") and it wouldn't be all that intrusive.
The biggest fear claimed by some writers of the legislation, and perhaps a justified one, is that cookies can (are?) be used to discriminate. If I remember correctly they cite a case where a large publisher could sell the cross-domain surfing behavior of people to insurance companies, recruiters, marketing bureaus or that it can be seized by the police, or leaked to hackers. It is akin to the reason why security cameras, if facing the public, must have a disclaimer sign with: "I am recording you". The cookie must inform the user: "I am tracking you". Right now, most users are unaware cookies even exist.
I agree my surfing behavior should be private, but I don't agree with the strictness and ambiguity of this law. The intentions may be right, so I don't expect them to even enforce it. As long as you don't violate the WBP ( Dutch Data Protection Act from 2001) you are ok IANAL.
That does mean if you build a recommendation engine in Holland you must comply with the WBP (secure architecture, handing over specific user data on request to a user, etc.).
One way to combat this is by using a hash. A salted hash that is untraceable to a user, but build from its IP, allows you to track the user, without the police or hackers stumbling upon personal data. Advertising and user tracking could apply this same principle.
As for the exodus, I believe it doesn't matter where your company or server is based, it is about doing business in Holland that matters for this law.
Also, the extensions I've seen have not so great usability. For example, I don't know any extension for Chrome, which would say "This page attempts to set you a cookie (details). Accept?" after login form submission (but not bother me with ordinary page views, 3rd party domains and other typical tracking/analytics stuff).
From my understanding of RFCs, cookies are offered, not forcibly set. User agents may store them or may discard them at their sole discretion. If there are concerns (there certainly are) about too lax cookie acceptance policies in popular UAs, it's UAs, not sites are the ones that should be fixed.