Implementing New Cookie Law Drops Use by 90%
chinwag.com
chinwag.com
That's kind of the point of the law. People should be free not to be tracked.
Here's an interesting question, though. Does the law prevent you from preventing users from using the site if they don't accept the cookies? Free websites each some of their money from advertising, and they optimize that advertising (among other things) with tracking cookies. If websites start demanding that you accept cookies, it won't be long before there are 'auto-accept cookies' plugins and such for lazy web users.
Because let's be honest. If people -really- cared they'd block the cookies with a plugin or refuse to visit sites that use them. And most people haven't.
This is why the effect of laws should be thoroughly researched before they are passed. Hoping for the best isn't good enough.
I believe that some level of tracking should be allowed by default, unless a user goes out of their way to avoid it.
Much the same as walking into a supermarket, I don't want them knowing what shop I just came from, and what I usually buy (unless I sign up for that stuff), but if they want to count how many times I visit in a week, or what sex I am, anonymously, why should I get a say in stopping that?
Possibly biased given I work in digital marketing, but I don't think so.
It would be much more transparent as to what the site is tracking and relatively easy to police.
The industry in The Netherlands continues to implement the opt-out registry found at www.youronlinechoices.org, since it sees the law as not technically possible.
http://www.iab.nl/2011/06/21/kamer-stemt-voor-ondubbelzinnig...
Google translate: http://translate.google.com/translate?js=n&prev=_t&h...
If 90% say no to a dialog there probably isn't much point in asking, and asking probably turns people away from your site. The only reason that this kind of stalking didn't turn people away in the past is because it was hidden from them.
http://en.wikipedia.org/wiki/Negative_option_billing
When Parliament went to ban the practice, the cable monopolies had the giant brass balls to complain that if they actually had to ask consumers if they wanted to spend money on new channels, the consumers would say "no," which would hurt the television industry. Whereas if they could just start charging money and force consumers to pick up the phone and cancel the service, well, people wouldn't do that.
Appalling, and it seems to be the same mentality at work.
Secondly, and more importantly, you make it seem like the user is merely an innocent victim, however the user is choosing to use a browser which accepts and explicitly sends cookies with every request. If they don't like that they are free to turn off cookies in their browser, or use a browser which doesn't accept cookies.
edit: fixing typo
The ethics of that position break down if you're offering an essential service and everyone takes the same view: now people have no choice but to be recorded, even though on privacy grounds that isn't necessarily a good thing.
The solution to that problem is to legislate that people's personal privacy outweighs a business's desire to track them, and while the specific rules we're talking about here are perhaps not ideal, I think going in that direction is going to become more and more important in the next few years as automated data mining technology can be used to profile ever more details about ever more people.
What supermarkets don't do and what cookies do allow now is for you to track said user over multiple visits. If I go to a supermarket and buy food and pay with cash, they don't have a record of me having come in three days ago to purchase the exact same items. With a cookie that is set for 12 years in the future you will know it is me visiting again, and again, and again.
Rather than trying to prop up a dying business model, we need to develop new ones that do cater to the needs of both consumers and providers. I suggest we try the radical "we make something you find useful, and you pay us a fair price for it" model that I hear was used by a couple of bricks 'n' mortars places with some success. :-)
Edit: I would gladly pay a small flat fee for, say, a month of access to the BBC's web site, provided that this could be done with trivial effort and with decent tools to track my total spend and some sort of simple refund/guarantee policy that works for any site using the system. If that also means I can throw a bone to other sites I value to help with their running costs, I don't have a problem with that either.
If browser fingerprinting or other covert tracking devices aren't spelled out in the law, this isn't going to mean squat. If you're not familiar with this technology, go to http://panopticlick.eff.org/ and see just how unique you look. You'll be surprised.
Edit: Also, the law does not make cookies illegal. There is way too much FUD in the discussions of this topic. The rules are about restricting cookie use (a) without explicit user consent and (b) to do things that aren't necessary to provide a service the user has requested.
The basic position is not unreasonable, they're just perhaps not going about it in the most helpful way. But most of the vehement criticism is coming either from people who don't understand or from people who have built a business model by doing unsavoury things and don't like that they just got spanked for it.
EU citizens will complain about this law when the web starts to act like Windows Vista, constantly asking for your permission.
I also had cause to visit a handful of other government web sites that day. Every single one of them was blatantly illegal under the new laws.
That is, if you want to track your users - that's fine, use as many cookies as you like and don't ask anyone's permission. But it's your job to do the tracking, you can't outsource it to Google.
I'm afraid you are indeed entirely wrong. The rules are not specific to third party cookies. There are some very tight exemptions for cookies or similar technologies where their use is genuinely necessary to provide a requested service, such as for remembering that someone is logged in or the contents of a shopping cart. Anything outside that scope, including using the same cookies for tracking/advertising purposes, is against the rules without explicit user consent.
As someone elsethread pointed out, if this is taken seriously, people will just start browser fingerprinting. That at least means that the information is stored server-side rather than client-side, which the new directive seems particularly concerned about.
Tracking within your own website for analytical purposes doesn't fall under the functional interpretation of "strictly necessary"; your site continues to function just fine if the Google Analytics beacon isn't fired, or can't distinguish between a first-time visitor and a repeat visitor or follow a particular user through the site.
I have heard people argue that analytics are operationally strictly necessary; that we need some insight into the behaviour of site visitors in order to operate an online business effectively. There may be something in that interpretation, but I'm a lowly web architect, not a lawyer. As such, I would be wary of accepting this more lenient interpretation without significant input from someone more schooled in the laws of our land (or any land, for that matter) than I.