Data protection ‘shake-up’ takes aim at cookie pop-ups
bbc.co.uk
bbc.co.uk
The problem is that I’m sure the general public will be in favour of removing those banners.
This is like dissolving public education to remove those pesky exams from children’s lives.
If aligns with Tory business interests so taking everything into account I’m sure it will go ahead but the level of dishonesty is surprising.
I’ll be paying attention to anyone calling this out.
Of course the ad companies rely on the bad and obtrusive pop-up design to annoy users into clicking accept.
Unfortunately that isn't adequately enforced so everyone gets away with making it a massive pain to reliably opt-out and very easy to accidentally permanently opt-in.
They're (supposed to be) the ones you can't get rid of, sessions and that. Stuff that would break the site if you couldn't track state across requests
> Data adequacy in this sense means an agreement that the protections in place are similar in two countries, with the idea of ensuring that personal information remains safe. It is a key part of EU regulations and was a minor sticking point in the Brexit negotiations.
- Bad decisions wrt handling the Afghanistan situation
- The potential weakening of workplace safety laws (starting with the relaxation of rules for lorry drivers, so they can be worked harder to fill the current gap instead of pay/conditions improving to attract more workers) and other employee protections post brexit
- ...
It is not unlike the tampon tax thing. They made a big deal about those no longer being subject to VAT on “brexit day” when in fact that had been agreed by the EU more than two years earlier and could have been implemented there and then (so women kept paying the extra for that time just so the government could claim a cheap win at the end of that part of the process).
Just a case of perverse incentives and conflicts of interest.
I mean I think regulating it in either place is a bit silly, but if we are going to force users to accept cookies on each site, putting it in the browser is far easier to enforce (since you don't have to go after each site that doesn't do it), and a much better user experience.
They're going to torch all our data regulations, and the only thing people will care about is the cookie pop-ups going away.
The U.S. has them, not because of data protection in the U.S. but because of EU enforcement. All thos will do is change the legal basis and likely keep the cookies
The solution to the problem of loads of web sites making illegal cookie nag-screens isn't to relax the laws so that they can legally steal our data - it is instead to actually prosecute for the nag-screens.
Details about what this really means, who will get access to the data, and what regulatory or legal consequences they will face if it's abused are disturbingly vague. In theory, there has already been a two-month delay in doing this due to concerns the first time around about a lack of public awareness. I have seen exactly zero further public information campaigning on the subject during the additional time.
Right now, as someone who believes strongly in the importance of personal privacy and restricting the sharing of sensitive personal data, I am more concerned about that imminent development than this one.
For anyone in the UK who is concerned about that, there is still just about time to opt out via NHS Digital's online system. Make sure you also notify your GPs, as it seems there will now be two systems involved and they require separate opt-outs.
(I'm using "UK" here, but if this affects you, please be aware that the rules may differ depending on whether you're in England, Scotland, etc.)
It's difficult to see how the other part (run centrally by NHS Digital based on the GP data) could go ahead without this part in place, so maybe they really did listen to reason and back down until they've got proper measures in place.
That would actually be quite reassuring in connection with today's announcement that we're discussing here. If those in government really have understood that there are some lines that shouldn't be crossed when it comes to privacy and personal data and they really are genuinely interested in getting rid of the excessive red tape that some of the EU rules do impose on anyone working with personal data, this might be a positive story after all.
We are so fscked
It’s not like framing your “consent screen” in a giant modal is going to make up for the 100 checkboxes behind the “advanced” link that each require a separate HTTP request to disable. Or that after disabling them, you’re lucky if they stay disabled for longer than the page session. And it doesn’t shake the feeling that “disabling” a tracker generates more signal than the tracker itself.
Anyone who implements this at their company is an idiot and an enabler. The profiteering companies encouraging the practice are little better then Outbrain, Disqus or Google AMP – an absolute cancer on the web. Oh, and I bet they’ve got lobbyists too. If you work as a developer at a company building consent modals, you are truly a useful idiot.
I'm slightly worried about all the other stuff they mentioned. Sure less red tape is nice, but it's a fine line between less box-ticking and simply no protection at all.
If eroding, still woefully inadequate, data protection, instead of simply mandating improvements to deliberately broken UIs, is the first thing future "Information Commissioner" intends to do, God Save The Queen's Browsing History!