You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking.
A session cookie, selected theme etc is all fine without that banner
You don't need a cookie banner to be allowed to create Cookies. You only need them if you're using them for something like tracking.
A session cookie, selected theme etc is all fine without that banner
Agreed. I can't think of a more widespread and effective campaign by an entire industry to gaslight their customers into hating a regulation more than the invasive practice that is being regulated.
So people pay with their privacy, some because they are tricked into it, some because they don't care.
Point is that invaison of privacy is bad and you should not have even an option to trade it for "free shit".
Giving someone with a website an image that they put up there is simple and requires zero cookies. If your goal is to have people see that banner this is literally all you need to do.
But of course advertisers want targeted ads, they want to get metrics (they don't care how truthful those metrics are, but who cares right?).
I for one need this data on a daily basis to help me decide how to make products better. I think the legislation doesn't do it's job properly. Why not force it so that like apple, the browser informs the websites that they don't want to be tracked, then it is the websites issue if they are caught tracking. Or all browsers forcibly obscure a users PII.
The ad industry believes targeted ads are cheaper and more effective in aggregate than un-targeted ads.
Also if the website is selling PII to “partners” as another revenue stream the the website cares.
When publications online went from trying to build an audience to trying to drive traffic we ended up with the situation we have now. They don’t have audiences anymore, they have atomized bits of content without much in the way of editorial voice or culture to tie it together. They care not one whit about making their site a destination, just trying to chum the waters for whatever will bring in a catch of fresh eyeballs.
Analytics companies that try to sell their analytics will of course tell you that you need analytics, but I just don't think it's true.
The only analytics I need are sales numbers. When they go up, I know I'm on the right track :)
The way I learn about my customers is that I put my email address on every page of my website. And then I read emails that folks send me, and this way I learn way more about my customers than any analytics could tell me, all without invading someones privacy.
(There is one exception: My apps do send crash reports, but they only send stack traces, no user data, and I don't log any identifiable info like IP addresses.)
Postulate 1: This website is free.
Postulate 2: This website does not use tracking cookies.
Theorem 1: Tracking cookies are not required for free websites to exist.
Postulate 3: This website is an ad.
Theorem 2: Ads do not require tracking cookies.
Note that my original comment asserted Theorem 1 only.
… and/or were more often genuinely grateful for things that were given freely and generously …
People wanting free shit is a constant. The problem is how we channel that desire, which is very much in our control.
You _absolutely_ can have free stuff. I remember the web when it was run by hobbyists, and that's exactly how it worked. What people who use the "no free stuff" argument really mean is that there are those who are on the web to make money, and you can't have their stuff for free.
To that I'd say; take your stuff and go home. Your stuff is exactly what ruined the web in the first place.
> Nowadays internet is too populous and expectations are set too high for this to keep working.
I agree with you on both counts, and would like to see a return to a niche web that doesn't work for most people.
EDIT:
P.S. I realise how unlikely that is, so it's not something I'd waste energy on. What I do think is worth thinking about though, is how impossible certain companies are making it for the niche web of the early days to even exist in its own little corner.
That would be a web without Google, and in fact any search engine at all. Do you really want to go back to 1990 level of functionality?
What I'm objecting to is it not being possible for even the old farts like me who want it. Google and co.'s contributions to things like e-mail and websites have made it more and more unfeasible to self-host and manage these services. It's a bit like how you're _technically_ free to farm your own food, only not really because you can't comply with the regulations surrounding growing crops (no I'm not kidding, Google and gasp).
Gotta love American's way of doing business
2. In the event (1) is too much to ask, all website importing our privacy setting from a unified service where we can do our privacy customisation once and for all.
In other words, for all these news sites doing it, "just stop".
Instead, have a simple modal with confirm and cancel in the proper locations, and just use checkboxes. Have every one deselected to start with as if someone is viewing that modal they’re likely about to disable all of them.
That is a common misunderstanding of the ePrivacy Directive [1][2]. It applies to all cookies (and "similar devices") that are not "strictly necessary in order to provide an information society service explicitly requested by the subscriber or user". And "strictly necessary" is quite a high bar.
(not a lawyer)
[1] https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...
[2] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL... See especially (25).
> strictly necessary in order to provide an information society service explicitly requested by the subscriber or user".
Sounds to me then that login/customizations are allowed
Per default you could not gather statistics but ask inside you app if people are willing to participate in making the app better and if they would agree to accept some cookies for this reason.
Maybe the key is to have stats that are purely anonymous, eg, how many people visited this page.
(still not a lawyer)
For your specific question, I think the Planet49 ruling gets pretty close. "It does not matter whether the cookies constitute personal data or not - Article 5(3) of the e-Privacy Directive (i.e. the cookie consent rule) applies to any information installed or accessed from an individual's device." [1]
(still not a lawyer)
[1] https://www.twobirds.com/en/news/articles/2019/global/planet...
However, I don’t think the regulations have an explicit safe harbor along the lines of “You’re fine as long as the math checks out”. Perhaps if it did, we wouldn’t be in such a mess.
(A passive observer that sees a JSON POST wouldn’t know that you’re using differential privacy. It would look like typical telemetry. They’d have to read your code or look at multiple samples and notice that the data looks random)
The latter is easily gathered from web server logs, the former sounds like a case of "I want to do this bad thing (spying on users) for good reasons", and the law only cares that it's a bad thing, not about your reasons (or arguably it does care slightly about your reasons, but not in enough detail to accommodate your use case). Laws being rather blunt tools and reasons being rather hard to divine.
You can get a bit of that via referrers, but not as much as you would like.
On the other hand, there are many things that sites do that are not fully explicit. For example, shopping sites often show you items you have recently viewed to facilitate comparisons, or a news site showing ads might want to make sure they don't show you the same one over and over. That doesn't sound to me like it is strictly necessary for the functioning of the site?
[1] "users are provided with clear and precise information in accordance with Directive 95/46/EC about the purposes of cookies or similar devices so as to ensure that users are made aware of information being placed on the terminal equipment they are using"
> Strictly necessary cookies — These cookies are essential for you to browse the website and use its features, such as accessing secure areas of the site. Cookies that allow web shops to hold your items in your cart while you are shopping online are an example of strictly necessary cookies. These cookies will generally be first-party session cookies. While it is not required to obtain consent for these cookies, what they do and why they are necessary should be explained to the user. [1]
> Receive users’ consent before you use any cookies except strictly necessary cookies. [1]
Generally, it matches my expectations. Shopping carts, sessions, and even most user preferences are fine and don’t need a banner. Worst case a small “uses cookies” text next to a language change button is enough.
"A cookie that is exempted from consent should have a lifespan that is in direct relation to the purpose it is used for, and must be set to expire once it is not needed, taking into account the reasonable expectations of the average user or subscriber. This suggests that cookies that match CRITERION A and B will likely be cookies that are set to expire when the browser session ends or even earlier. However, this is not always the case. For example, in the shopping basket scenario presented in the following section, a merchant could set the cookie either to persist past the end of the browser session or for a couple of hours in the future to take into account the fact that the user may accidentally close his browser and could have a reasonable expectation to recover the contents of his shopping basket when he returns to the merchant’s website in the following minutes."
I was using the website for a Dutch big box hardware store (Gamma) today, and it had a door stopper I was looking to purchase half a year ago in my shopping cart. I never finished that transaction. That kind of retention is just pointless.
A session based cookie can then be used to store your identity in a short term session, and the server can easily gather long-term storage on its own.
I think it’s a fair compromise to say “if you want to save this cart, please log in”, which satisfies opt-in data tracking in a user friendly way. You aren’t mandating a user account, but if you opt in you get something potentially useful.
My principle complaint about most of the discourse on this topic is that it is superficial. There are reasonable workarounds for most user-friendly tracking that allow for tacit opt-in via responsible and clear UX. The “hard parts” seem to generally concern the type of tracking that isn’t so clearly user-friendly, such as behavior tracking and PII collection, which is a conversation we should be having anyways without obfuscating the issue by pretending it’s about the easy stuff.
For example, remembering things like Dark Mode, pop-up re-sizing, slider locations (volume for example) are all legitimate use cases that I would prefer as a user to be isolated per client.
Since the site does not know you are leaving, it doesn't have any opportunity to prompt you and ask whether you would like to save your cart (and if it did I would find it pretty annoying)
I do. I use the shopping cart as a staging area sometimes when deciding what to buy. In fact, I don't really see a good reason for a shopping cart ever lose items I put in it until I explicitly remove them or they stop being available, since the whole point of a cart is to express intent to buy.
At the very least if a site doesn’t offer Wishlist, shipping list or other bookmarking facilities I would expect the shipping cart to give me a cookie that lasts at least three days to cover the weekend or the option to create an account to save that shopping list/cart to come back to later.
Path of least resistance wins.
That's a pretty bold claim, even steel-manning it. I personally only ever see it on sketchy sites. If you're right, then it would just take a campaign of education to halve the annoyingness rate of the internet.
I looked just now on StackOverflow in incognito and saw no obnoxious pop-up.
Agreed. The practice is widespread among sites regularly linked on HN.
Just checked again (not even incognito) and it's there.
Your privacy
By clicking “Accept all cookies”, you agree Stack Exchange can store cookies on your device and disclose information in accordance with our Cookie Policy.
Accept all cookies
Customize settings
I've read this entire thread and I still don't know when I would need to prompt for cookies, or even if I need to prompt if I store everything serverside and id the visitors with a session token in URLs.
There is no easy-to-understand definitive answer for the common use cases.
Well that's the problem, right there! You're reading random HN threads to get this information. Why not go to the source?
https://ec.europa.eu/info/law/law-topic/data-protection_en
The law itself is fairly easy to read and understand if you're a software developer.
https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
Here is what looks to be pretty respectable commentary on when it triggers. Essentially, if you collect any sort of personal data whatsoever: https://gdpr-info.eu/issues/personal-data/
If you store information that can identify the user, e.g. if you collate a user's IP address, you are almost certainly collecting personal data.
Don't, if you can help it. If you must, that same site has some general guidance on how to collect consent: https://gdpr-info.eu/issues/consent/
Read there more info on how to comply with the data collection. Essentially, if it is personal data, you must give the person informed control over their data, including the ability to withdraw consent at any time, in which case you must delete it.
$ wc cookie-regs
4198 54871 354380 cookie-regs
54,000 words? Significant fines for non-compliance, even in the form of errors? And this is a legal spec, not a software spec, so there's no validating my implementation? And the terms are subject to possible change and different interpretations as one could get sued in any country?Or just put up the cookie notice and not worry.
Do you have examples of this? I mean the different interpretations meaning that one country could sue you for an implementation that was deemed fine in another one.
Ok, but EU legal systems (after Brexit) I think are all Napoleonic systems and not common law, furthermore as the 'cookie law' is a directive and not an actual law and is thus supposed to be imposed the same way across all EU lands I don't think this could be as exploitable as it might otherwise be.
But even so as it's a directive I don't think it is open to interpretation the way a law might be.
> ...Napoleonic systems and not common law, furthermore as the
> the 'cookie law' is a directive and not an actual law...
And the fact that I have no idea what "Napoleonic systems" are, nor what "common law" is and how that differs from non-common law, nor what the difference would be between a "directive" and an "actual law", all shows why I won't understand that fifty thousand word spec.Of course, I could go get an education in law. Or I could implement the cookie popup.
<https://upload.wikimedia.org/wikipedia/commons/9/92/Map_of_t...>
You don't appear to have the aptitude to educate yourself when you notice that something confuses you or you are ignorant about a topic, c.f. post id=29529880.
I do not live in the EU. I did not learn what civil law nor common law is, neither did I learn the difference between regulation, directive and national law. Out of interest, I work with people who grew up in France, Russia, the United States, and Argentina in addition to locals. I'll ask them if these terms are familiar to them.
Perhaps in fact I don't have the aptitude. Or more likely, I see the tradeoff between "understanding every nuance of a 50,000 word document in a field I'm unfamiliar with that carries severe penalties for my client" vs. "implement cookie warning" differently than you do.
I could give you layman definitions good enough for this discussion in about half a dozen words each... But, hey, let's not reward auotingrained helplessness.
Anyway, if you feel the need to implement a cookie pop-up to feel safe, I get it.
The GDPR is really meant to protect users' rights to control their own data. If you implement that single principle in good faith, there won't be any gotcha moments where the EU cyber police fines you over some obscure clause in 50 thousand words of legalese.
It's really the people who ignore or circumvent that principle who will be crushed.
In my opinion, you will be serving your clients better if you take the time to understand the GDPR rather than annoying your client's users by cargo-culting UX from companies that are skirting or ignoring the law.
If you do want to cargo-cult anyway, you could do worse than to crib from the EU website itself. Just saying.
https://ec.europa.eu/info/law/law-topic/data-protection/data...
For what it's worth, I completely agree with the spirit of the GDPR and don't really have an issue with the implementation - it's far better than not having it.
I get what you mean but technically its not compliance, as the law requires a simple yes no option. Definitively malicious though.
Citation needed.
What about In Browser databases? Or Javascript?
It's much more than just cookies that are stored on computers.
"The storage of information in the end-user's terminal equipment or the access to information already stored in the terminal equipment shall only be allowed if the end-user has consented on the basis of clear and comprehensive information. The information to the end-user and the consent shall be provided in accordance with Regulation (EU) 2016/679."
If it is absolutely necessary for the requested functionality then it is allowed. Therefore it doesn't really change anything.
The language of the new law in Germany is virtually identical to the language of the EU directive. So why would it be different in Germany versus other countries in the EU that also have to implement the directive?
Privacy law in Germany is usually stricter than in other EU country's even if the text is identical.
And the main argument of this thread initially was that you don't need to ask if you are only using cookies for such use cases.
This Podcast explains the topic much better than I could:
Rechtsbelehrung - Recht, Technik & Gesellschaft: TTDSG – Cookies unter Aufsicht – Rechtsbelehrung 102 https://rechtsbelehrung.com/102-ttdsg-cookies/
https://noyb.eu/en/noyb-files-422-formal-gdpr-complaints-ner...
That's not functional though, is it?
I understand entirely the desire to use such a thing, to understand how your site is being used, but it's not functional in a "delivering service to the end user" way.
(Personally I like the way it sounds, analytics without signing over the world to Google, but it's still not functional)
> It’s possible to disable tracking cookies in Matomo by adding a line on the javascript code. When cookies are disabled, Matomo data will become slightly less accurate
So it seems there's no "functional cookies" in Matomo, and so all cookies from Matomo without consent popup is not in compliance. You can disable all Matomo cookies and allow for compliance:
> By disabling tracking cookies, you may also use Matomo without needing to display a cookie consent screen.
It is. There is no other law about cookies.
This shall not prevent any technical storage or access for the sole purpose
of carrying out the transmission of a communication over an electronic
communications network, or as strictly necessary in order for the provider
of an information society service explicitly requested by the subscriber or
user to provide the service.
English version of the response from the EU court:https://curia.europa.eu/juris/document/document.jsf?docid=21...
Part of this case at the german 'Bundesgerichtshof'.
https://www.bundesgerichtshof.de/SharedDocs/Pressemitteilung...
> Die Einwilligung nach Absatz 1 ist nicht erforderlich, wenn der alleinige Zweck [der Speicherung oder des Zugriffs] die Durchführung der Übertragung einer Nachricht über ein öffentliches Telekommunikationsnetz ist oder wenn [sie] unbedingt erforderlich ist, damit der Anbieter eines Telemediendienstes einen vom Nutzer ausdrücklich gewünschten Telemediendienst zur Verfügung stellen kann.
>vom Nutzer ausdrücklich >gewünschten Telemediendienst >zur Verfügung stellen kann.
Now we have to document that the user wanted the feature that needs the cookie...
I don't think it's as simple as that.
So technically necessary cookies still don't need consent.
The issue with Matomo is that even though nicer than Google Analytics it is optional for the working of the website, so it should only activate if the user consents.
There is some serious cargo culting regarding these kind of laws going on. I remember back in the day that you would add "I don't take responsibility for the external links" kind of disclaimers on every website. Or everyone thinking they need a Impressum (legal info/contact info) page on their website because it is required by law. (No only for commercial sites, which is reasonable.)
I just listed it as an example where people don't understand the nuance around an issue. "You better provide some Imprint if you are in doubt" becomes "You are required by law to always have an Imprint"
Selling Windows by default with every computer is now illegal in Germany then?
No one gets tricked into approval (here: buying) because every customer is able to request a different or no OS, or to reject an immutable sale offer; except if you think that not knowing what an operating system is and what it implies constitutes a trick, but that does not meet the legal definition.
Also lawyers are expensive and many of them will just tell you to add a cookie banner to your site. They're also lazy and just trying to cover their asses too.
Imagine if instead of the obnoxious cookie banner, browsers ship with a default “don’t accept cookies” or “don’t accept 3rd party cookies” setting. When a website needs to establish a session, the browser would prompt the user, “this website uses cookies to track…”
If the user gets annoyed with that setting, they could change the default to let any website use cookies.
It’s really obnoxious how this issues was pushed into website operators and not browsers.
And so it marches on - most legislation ends up making things worse instead of better, and there is no accountability because we blame the wrong people for it.
My favorite example are sites which require you to opt out of hundreds of third party processors individually (advertising partners who may receive data). That's as dark a pattern as it gets.
It's also in clear violation of how opt-out is actually supposed to work, at least in the EU.
And with the Do Not Track header, I shouldn't even have to opt out in the first place. A GDPR decision to that effect could solve this banner madness once and for all.
At the very least, I've stopped setting it since no website respects it.
The whole "users didn't opt in" thing was a false narrative manufactured by the ad industry. You don't need to ask a customer to disable bad behaviors without asking.
"Let's ask these bad actors to play nice, I'm sure they'll respect that, I mean, they probably think we all want to be tracked so let's just tell them we don't and it'll all be fixed. And make sure the option isn't obvious enough that normal people start to use it and ruin the whole thing".
Enforced DNT is part of the ePrivacy Regulation, which was supposed to launch alongside GDPR, but got delayed. Expect it to arrive somewhat soon.
https://digital-strategy.ec.europa.eu/en/policies/eprivacy-r...
You're right, but I'd like to mention that, in pretty much every jurisdiction with laws like this, you cannot set or retrieve information from a user's computer without getting their consent first. Which means that accessing cookies on page load, then showing a consent banner, is no more protection then just not having a consent banner. I would always tell clients this, and even send them the relevant wording, but I don't believe it ever made the tiniest bit of difference because, as you say, they just want to keep tracking users.
Clicking "I accept" means you can't sue a website if they have your data.
I'm not sure but I don't see why those websites would annoy users.
You don't need a "banner." The requirement, as I understand it, is to be conspicuous. Conspicuous just means visible, easy to notice. Contrary to the industry's apparent position, conspicuous and obnoxious are not synonyms.