New EU data blockage as German court would ban many cookie management providers
iapp.org
iapp.org
This is a perfect example of the kind of legal processes we have now.
The EU and Germany in particular have decades of privacy regulation and core values behind them. These core values won't change. Regulation for the past decades has ignored that tech routinely violates these values, and it's catching up now. Rules won't be as dramatic as in the past, but will differ widely from the us.
In this context, it's legally important to account for entrepreneurial freedom (guaranteed by the constitution), but if there's an overriding reason to protect consumers, then it is entirely irrelevant how long companies have been doing this, how many do this and in what other countries they do it.
To sum up, the law sometimes bites late, but it bites hard, and arguments surrounding competitiveness, business culture or internet culture are legally completely irrelevant.
One of the biggest legal changes in the past few years was a new direction altogether to determine anticompetitive behavior.
If I recall correctly, FB’a recent acquisition of giphy (?) was also stopped on anti competitive grounds.
Point being that this stuff isn’t necessarily easy, the other side has very good lawyers who tell them what not to do on top of this being novel.
It’s not unique at all. The old trusts that were broken up at the dawn of antitrust (that’s where the name comes from) were of a similar structure and even more dominant.
The “consumer harm” test (really “short term consumer cost” test) was a deliberate crippling of antitrust doctrine during the Reagan era. The process is only now starting to return to its roots.
Consumers can be harmed by a low price when it is predatory, either to drive out competitors (so price can go up later) or to transfer business to a monopolist who can charge higher prices elsewhere and/or stave off competitive technological or entrepreneurial threats. This doctrine blessed such predatory tactics while pretending to be a high-minded consumer-friendly approach.
I'd like to cynically say that the rhetoric and arguments have finally started to return to their roots within this particular administration, but there's no evidence of a process actually being carried to completion yet.
It’s heartening that things are shifting, but it’s bound to be slow progress.
The fundamental hope that democracy is based upon is that they will eventually (in finite time) grind all problems, even if not right away.
It's important to remember that 100 years ago (if you squint, 150 years no contest, there basically was no democracy in the modern sense (universal suffrage, no special rights), kings and queens and aristocrats still held most power and wealth in most places around the world. It's very easy to forget that the descendants of these aristocrats in places where lasting measures against the lingering power of the old rich weren't taken (i.e., they weren't executed and their wealth was left intact) are usually still in the richest 100 families of the country and wield considerable political influence.
I will stop here now because dang has repeatedly asked me not to make statements likely to inflame "boring" political discussions but I do think that as more and more people realize that they are not in fact temporarily embarrassed millionaires the old power bases of corruption and uncapped dynastic wealth will follow the way of dynastic hegemony over nations.
I no longer believe this to be the case. I am pro-democracy but I am not a suffrage maximalist. During the last election cycle I looked at the myriad of obscure positions I had the right to vote for on the ballot and I realized most of what I was voting for I was unqualified to weigh in on.
For instance, why do I vote for the Railroad Commissioner? Why do I vote for my local county's community college board of trustees seat 5 and 6? You could say that I should be informing myself before I go to cast the ballot. While you wouldn't be wrong for saying that is my responsibility as a voter, I can assure you virtually no one actually does this. I also find the down ballot candidate's pitches so generic and milquetoast that there isn't enough substance to actually distinguish between them.
What's worse is that the obscure positions have either unopposed candidates or just two. And most of the time, people just look for the (R) or the (D) by the name and that's what they go on.
:-(
Fortunately antitrust appears to be moving back to its century-plus-old roots.
I always thought this. I was recently introduced to the concept of “practice prevails” whereby if you’ve been routinely flouting a rule, and that rule has never been enforced that you can claim the rule is obsolete. I think it’s mainly confined to contract law but it does help to explain the standpoint of those who oppose such retrospective regulatory measures.
I hear what you're trying to say, but there are problems with this basis.
There is no clear established legal-nexus between the your purported statement of "protecting consumers", and banning the use of any data center owned by multi-national corporate entities who host protected data exclusively internal to the EU in accordance with all known EU data-protection regulations. Now to be clear, I'm not saying this is your statement or position.... but it's what you wrote.
So it boils down to a false-dichotomy; This is protectionism, but not to be confused with consumer protection. The protectionism is the kind protecting EU owned & operated data centers.
I think analogies are awful, but to give an analogy it's like banning a product sold by any multi-national corporation simply on the basis they are not originally EU multi-national corporations. For instance, banning the sale of McDonald's chicken-nuggets, because McDonald's is a foreign corporation, and then alleging the corporation violate the consumer data protection laws because the nuggets are not EU nuggets
It makes no sense because there is no causal-link or rational basis, it's all irrational. Just because irrational laws have been the norm for a while, as you say particularly in Germany, doesn't make them rational now. That's a variation of the ad-populism fallacy.
I think you are mistaken here. Strong privacy laws in Germany are decades older than Facebook et al., and to some degree have constitutional level. Similar for other EU countries before the europization of the variants of national law (which actually weakened German privacy and consumer protection law in some minor details).
Big Ad companies have a core business model that is simply incompatible with the values implemented here. That is the whole secret of why there are so few Big Ad companies founded in the EU. Calling that anticompetitive is mistaking cause and effect.
I also think you are overestimating our ability to rationally observe, understand and predict things in society. Part of the reason why we have these laws is that it is so incredibly hard to predict the outcomes of any intervention.
Of course there is the threat of over-reach, but it's always there. On the other hand, we have plenty examples where lack of regulation lead to massive harm (environmental pollution, medical experiments, monopolies etc). So there is no easy solution, and "irrational" regulation is definitely on the spectrum of sane ones.
Evidence-based policy-making is rare because there is lots of policy-based evidence-making.
It’s the same with the US.
The moment you want to monitor your users' behavior for whatever reason, though you need to ask them. They are not your guinea pigs.
I strongly believe you can have a great business, even do advertising, without selling out your customers/visitors.
And blaming the law because industry is using dark patterns to circumvent it seems odd to me.
Do I like these consent banners? Most of them not. Neither as consumer, nor as the one implementing them. But the hiddeous ones to me are a symptom of a rotten company not valuing their customers. Not a symptom of a bad law.
Then why would you implement them (assuming your company is not rotten), if not for compliance with regulation that failed to find the sweet spot?
But you might find it easier (or whatever) to integrate Google Analytics than set up your own Matomo instance, so you'll have to ask the users if they want their data shared with Google.
It's not as complicated as most companies want to portray it.
edit: I had our company website at this point. Locally hosted fonts, no external tracking, own Matomo instance, everything was great and I could finally remove the cookie banner. Then marketing came around the corner, wanted to run paid ads on LinkedIn and Xing, also it was "sooooo comfortable" to link Google Analytics with Google Ads and see how your campaigns perform. Now there are more external scripts than ever, we have Cookiebot (let's see for how much longer :-D) and a cookie banner with the usual settings and lawyer copy on it. I hate it.
I don't think that it is always trivially obvious how to correctly comply, like some other comments claim. Especially when you really want to eliminate all legal risk and avoid Abmahnfallen.
Because they are the path of least resistance. Companies don't want to spend any time figuring out how to actually be compliant, so they slap these cookie banners on, most of which aren't compliant.
Also they're not "cookie banners". You don't need to show a banner to set cookie that your site needs to function (such as login, etc.).
They're "we're doing stuff you didn't ask us to and sharing your data with over 300 other companies" - banners.
I use klaro.js as a consent tool. No need for a CDN.
I configured it such that on the first screen you can opt in, opt out or choose to choose.
I hate the ones (them being not in line with the regulations btw) that force you to go to the second screen for saying "no".
It needs to be as easy as one click for yes or no.
Absolutely. At the very least it should be legally required that "Reject all" is at least as easy and prominent as "Accept All" if we already started to legally require clicks for consent.
Yes, this is what it feels like.
Now.
Because the industry is in a Wil-E-Coyote moment. Their business model has always been more than shady, a shadiness that has now officially been defined as illegal.
Industry response to "you are not allowed to do this" has been "but I really wanna", and they think that they can get out of complying with the law via these dark patterns about tricking the user into giving them "consent".
All of this crap is illegal.
Tricking users into "giving" you "consent" is illegal, as is coercing them. The law is very clear about this.
It will take a while for the wheels of justice to grind, but grind they will.
In the meantime, we apologise for the inconvenience, but the world will be a better place.
Honestly it is, we are dealing with huge amounts of medical-tier PII data(not actually medical, but as vulnerable as as protected).
It's just that companies are reluctant to give up the profiling powers they get from their current system.
For obvious reasons, companies choose not to comply in that way, and ambitious companies will instead often test the limits of what the regulation actually prohibits.
This situation was wholly predictable the minute it was decided to pass laws to codify what were previously best practices. We now get to enjoy the same benefits the law has granted in the past on environmental protection, civil rights, labor practices, patents, and copyright... With similar grey areas, fuzzy and contradictory outcomes, and but-what-if attempts to augur the legal process. Not to imply any of those laws should never have been passed! Merely observing that when we use this tool to solve our problem, this is how this tool operates. The pattern is well-established and basically at least as old as rule-of-law.
If a company has to show 300 banners and asks for consent multiple times, it’s because they are doing extremely weird stuff. Legislation just made it visible.
There was a story yesterday about someone getting terribly upset about researchers probing the GDPR compliance of the website of a blogger. Some froth developed around people's mouths as the site in question was called a "victim" and any shrugs seen as "victim-blaming". (And I was thoroughly downvoted for pointing out that calling website owners "victims" was a bit more drama than was called for)
GDPR and similar legislation has, as you correctly pointed out, had disappointing results. There is no doubt that stronger regulation is needed to stop companies essentially spying on users for financial gain - just as there is no doubt that regulating this in a way that both helps, and doesn't just become an expensive waste of time, is hard.
And that's why I find the line of argumentation that says 'the consent law is fine, just give it more time' a bit frustrating. It is such a waste of time and energy, while it does not really tackle the core issue of data abuse, but it negatively impacts everyone's user experience.
I think that the law is not well adjusted plays a major role in the situation that we have today. We are in the fourth year of the law and I see no impulses that would lead to a world without full page overlays on most websites on first visit, where the only primary action is "Accept all". While I as a techie take the time to reject most cookies, the more tech-illiterate part of my family has already sold my firstborn child for a couple of news articles.
Every time I see one of the GDPR popups it incentivizes me to think "do I really need to access this content?" - and more and more often I just think "no" and delete the bookmark or make a mental note that "this website isn't worth the click".
That's actually a good question... how would you do that. I guess the website would need explicit consent to save a cookie with the information that you consent to nothing else.
That being said I don't really agree with the premise of your comment. A law that isn't applied shouldn't be considered a law, and saying "you should just have applied the law from the start" isn't always fair. For instance, in France, woman were not allowed to wear trousers until maybe 5 or 10 years ago. French privacy laws 1980s already had a real scope on privacy, but it was barely applied. Applying a 40 years old law out of nowhere would simply be targeted attacks to the current disgraced company.
Now, GDPR is really recent, so I won't put it in the "hasn't been used for so long it's dead" basket. Though I kinda think that the portability part of GDPR will (I'm crossing fingers it will still happen, because I think it's the best part)
That law was a dead letter from 1800. It’s the equivalent of the old English law memes, like that you can shoot an arrow at a Welshman within the precinct of Hereford.
It's not 200 years old, but it definitely is OLD.
(Disclaimer: Legal theory is slightly simplified, but true to principle)
But I'd argue that the roots of Germany's focus on privacy are not only rooted in protection against the state. Yes, constitutional fundamental rights are protections against the state (Abwehrrechte), but the legal interpretation established by the supreme court also draws on an ideal-typical perception of citizens as informed, rational and responsible people (mündige Bürger), who - through education, intelligence, moral values, dedication and pro-social behavior - create and sustain society.
Such self-determined citizens cannot exist in the face of overbearing, and especially invisible or intractable (!) external coercion. That's also the root of informed consent, of course. So in this sense, privacy protections are a safeguard against dumbing down citizens, and I think the general intent is indeed valid.
That's excellent, it's these type of arguments that get too little attention when digital "privacy" gets discussed today.
This is a foundational assumption of post-Hobbesian democracy, which asserts that power originates from the people and is delegated to the government (contrast to other political philosophies such as divine right of rule etc).
so the consequence of 'dumbing down citizens' is a destruction of the legitimacy of the government. Just as if the king rules by divine right, he would be silly to promote atheism.
I live here. Privacy awareness is very high, compared to everywhere else I've personally been. Nobody likes having their picture taken, nobody likes being filmed, nobody likes answering questions for strangers. And they'll tell it to your face too.
Go onto Google street maps for Germany and see how far you get.
And yet, people are amazingly complacent în other aspects ("War halt immer so"). For example, your apartment's doorbell has to have your last name on it: someone with an unusual name could conceivably be tracked down just by postal code. For another example, when I was blogging, I had to display my full name and address in an Impressum on the website - dox myself, so to speak.
And, of course, the Berlin government forces people to register their address, and allows everyone to query it, because why wouldn't they:
Meldepflicht is in all of Germany, it's not a Berlin thing.
> and allows everyone to query it, because why wouldn't they:
This is highly controversial, for exactly the reasons you might think.
However, this is an "Einzelauskunft", so you get one address per query, and you are not allowed to trade in those addresses or use them for advertising. Also, if you want more detailed info, you have to provide a valid reason for wanting them.
Same principle as with password hashes were you might prefer a slow hashing function with a work factor.
I don't necessarily agree with the streetview restriction, but also don't really mind not letting Google make pictures.
You actually don't need to put your name on your doorbell, but that at least has very practical advantages for yourself.
Berlin is a failure of government since time immemorial but I am not familiar with this law.
ephemerality. If you think your neighbor is violating your privacy you can take it up with them, you think you can take on Google? There is no incoherence here. If you live in a neighborhood, there are of course certain natural limits to your privacy given that you're part of a community.
But digital privacy laws first and foremost protect citizens from entities well beyond their control, they protect them from automated processing, storage of their data beyond their own borders, and privacy erosion in ways they cannot control and at a scale that creates entirely new problems. Of course nobody has absolute privacy, everyone can overhear a conversation, but this does not end with a surveillance state or control society. Corporate entities or governments processing billions of messages in real time does.
Uh...whose last name would you put on that doorbell? Someone else's who doesn't live there?
People constantly complain about the greedy tech companies collecting data where ever they can and proceed to complain about the strict privacy regulations in the EU in their next sentence. Forcing private individuals to put their full name and address into the imprint of their personal website, which often enough isn’t even run for profit, seems absolutely absurd and very publishing hostile.
To me it’s more and more starting to seem like people don’t actually care about their privacy, they just want to be against something.
Wait...so people can decide which facts about their life they want to remain private and which they're fine with you knowing? I thought that was the whole idea of self-determination. Where's the catch?
In my case it is actually the other way around. I had no problem with street view but would never list my number in the public phone book.
I selectively decide what to attribute to my name as long as I am able to. So that I for example decided that I am OK with the need to have an imprint on my website and my full name and address being tied to what I write there.
I understand that this isn't for everybody, but I decided that I was okay with attaching my name to my writing.
But I am not okay with random businesses being allowed to spam me via online generated profiles without me knowing or consenting.
I know there are a lot of things that still should be massively better in Germany. But knowing how easy it is to comply with the GDPR and relevant other regulations I actually like them.
That courts are ruling against this, in whatever way, is still a good sign.
When you get to the point where judges and lawmakers have, more likely than not, personal experience of threatening emails containing private information, there's a lot of incentive to reduce the amount of data collection - and correspondingly, a lot of popular support for the idea.
Even if that is the case, it would still not be an argument against such regulations.
If someone else is okay with the data transfer, he can opt-in if he wants to. I should not carry the burden of having to opt-out of it.
You are wrong. I have been living in Germany for almost a decade and it absolutely does. In fact, it is one of the things that I appreciate the most about German culture.
Maybe privacy preferences are a bit incoherent sometimes, but nothing is perfect, and I much prefer that we err on the side of protecting privacy too much than too little. Especially in this brave new world we live in, were culture is being slowly but surly manipulated by powerful interests to erode the right to privacy more and more.
https://joinup.ec.europa.eu/sites/default/files/document/201...
See page 55 for per country chart.
It's sadly the opposite; It's so normalized that a whole generation was born into it and don't even see anything wrong about it.
All a lot of them see is how Google is giving them "free services" and how Facebook allows them to make "free friends", and then they declare; That's the web, and that's how the web has always been and how it should be.
And who can blame them; They never knew any other web than the glorified digital mall [0] it has mostly become.
[0] https://staltz.com/the-web-began-dying-in-2014-heres-how.htm...
I find it problematic that the university requires any cookie consent whatsoever in the first place. They are a public institution (Körperschaft des öffentlichen Rechts), not even a "company" but state-owned, and they run basically a static website and shouldn't have a need for cookies. Any "member" area (students and faculty) would require an account anyway, where you can and have to ask for all kinds of consent during signup anyway.
I get the Danish company doesn't want to run a CDN (with DDoS mitigations and all that) on their own, and it's a real problem that the EU economy snoozed when it came to creating competitors to Akamai, Cloudflare, AWS/GCP/Azure. There is a sliver of hope that court decisions like this will create a "demand" for such platforms within the EU, and that finally some companies with some "investment" money to spare (we still have plenty "rich" companies) will fund that. Or maybe at least the US providers will find way to create EU "subsidiaries" which are actually legally shielded from US (and other non-EU) law.
Totally right, and also
> If someone else is okay with the data transfer, he can opt-in if he wants to. I should not carry the burden of having to opt-out of it.
so much this. If something is spiraling out of hands it is the cookie usage, which is 99% AD tracking.
The current law is badly implemented, or lead to bad implementation. Now almost every site asking your for their necessary or "helping" cookies, most often using dark patterns to trick you into just accepting all - and because you get this stupid cookie prompt on every page now, everybody just wants to click it away as fast as possible, which misses the target totally, too :(
Still, its not data protection spiraling out of hand, but that basically every site, even ones where I don't login to or want to drop off any other data, but just fetch a small information, wants to set cookies is ridiculous. We all should have never accepted that, but too late?
[0] a huge amount of misinformation going on, making people think there would be live cameras showing them on street view. At least to me, it felt like manufactured outrage by people who didn't understand what was going on (neither the instigators, nor the outraged).
edit: It was mainstream enough that there were articles about it: "Webforscher Humer glaubt, die deutsche Skepsis basiere auf falschen Vorstellungen zu Street View. Viele Menschen würden davon ausgehen, dass Google Live-Bilder übertragen wolle" - https://www.onlinekosten.de/news/webexperte-deutsche-versteh...
I remember more from the local press back then. But it's hard to find sources about it now.
so it kind of depends on what you mean by "I'll be going to the next day and prepare accordingly."
I know several people who have blocked their houses on Google and absolutely none of them had this assumption. Anecdotal, I know, but in the article there is zero data backing that assertion.
And then they wrote pieces about what kinds of idiots didn't want to have their houses filmed. And about people who had their shop front blurred, because people in the 5th floor didn't want the house to be in the clear on street view.
It was outrage porn at it's best.
And one of the things that made me decide that I maybe should do something else with my life.
that was in no way a mainstream "idea" about it.
The reason to allow data transfer to the US for (arguably) trivial data is that a private entity might choose Akamai as their subjectively best option. Restricting data flow for (arguably) no good reason puts restrictions on other who can invoke their own fundamental rights. Leaving aside that it’s also not great to force the technologically inferior solution for (arguably) moot policy reasons.
As to the argument of informed consent, I think that’s another severe misconception. In my opinion, consent is only one option to legalise data processing. The fact that GDPR (and older German legislation) lists legitimate interest is important. We should — in my opinion — not fall for the fallacy that data is a whole different universe that can be split off from everything else. For most of our lives, data just flows with contracts, relationships, torts and whatnot.
I do acknowledge that in the case, the university is Public and does not have (relevant) fundamental rights. Also that web analytics is likely one of the consent only scenarios. But we’re drifting into theory anyway.
Now you could certainly argue that this right is irrelevant/not needed, but you didn't bring forth arguments to this extend. Without this your argument is largely about businesses being inconvenienced (many European countries don't give businesses fundamental rights like they do for people)
And what if it's China/Russia, and its 'best' because it pays for private data? Does the argument still hold?
At the end of the day, this is simple: is it my data, or not? If it's my property, why should someone elae have freedom over it?
and your search results may be use to implicate you of homosexuality, or by extension your relatives in that country, and the country's police are monitoring search histories.
So much this.
This is evident, for example, from the very first sentence [1] of the GDPR:
The protection of natural persons in relation to the processing of personal data is a fundamental right.
[1] https://gdpr.eu/recital-1-data-protection-as-a-fundamental-r...
US law grants the US government broad (some would argue over-broad) reach into the digital activities of US-based companies independent of where those companies physically house their data. The great truth of the Internet is that it's a location-disrupting technology: modulo latency, the computer next to me on my desk and a computer in Sydney, Australia are logically exactly as close (by which I mean: fully equivalent whether I'm fetching data from one or the other as a client). But of course location still matters for the oldest location-focused institutions on the planet.
I predict that unless higher courts just decide to disregard the reasoning in this case, the resolution here will be either an international treaty between the US and the EU to clarify data access rules here or a simple jurisdictional mess: whether an EU citizen's data can be sniffed by a US company from computers in the US will be entirely up to who's government cares most.
What I am thinking right now: How will this affect me as European wanting to access US sites? There are already a bunch of sites that completely exclude European traffic on IP level.
It's great to have data privacy. I am totally for it. But it comes at a cost. People are not willing to talk about this cost, let alone take it into account when making a decision.
You get to live in a place that has (democratically) decided to put a particular cost on privacy. That cost being that you don't get to benefit from the cheap-ness of low-privacy offered in other places.
And we don't talk about this nearly enough. Everybody loves being able to buy super cheap clothes from sweatshops in Bangladesh. Everybody is still going to enjoy the football world championship in Qatar, played in stadiums built by what's effectively a form of slave labour.
We should definitely enforce our humanitarian values also through our trade and other agreements, otherwise they're meaningless.
Despite some politicians best efforts and desires, there's no practical way to stop someone 'importing' privacy damaging web traffic, so the risk of non-compliance is being loaded onto foreign website operators. Therefore should a US website desire to follow EU laws, there would be no restriction on them being accessible to EU people.
No matter how much privacy laws and regulations occurs within EU, it is unlikely that companies like google, apple, Microsoft or amazon will ever be willing to completely give up on the European market. There is simply too much money to give it up and have competitors take it. The websites that might be willing to exit the market is those that already have very little stakes to remain, like American news sites that focus on specific regions and demographics in the United States. For HN readers we tend to see those for time to time, but I doubt many other Europeans notice much of sites that already exclude European traffic.
changes VPN location to US
"Ah, an American, welcome!"
Everyone should be using a VPN. Of course, "Which VPNs can you trust?" ends up being a valid question and I'm sure that landscape will continue to evolve for the foreseeable future.
Everyone who accepts the rule of US companies.
If you have very specific needs, there might be something better than it. But no one ever got burned by choosing Mullvad.
What you are complaining against is that some sites are built around selling user data and EU makes it hard to do so. The cost you are talking about is your inability to form certain contracts. Every regulation comes at certain cost. However, in this particular case the data protection and safeguards against selling of such data are the basis of regulation, not the consequence. GDPR is born to enforce this cost and this cost has been integral part of surrounding debate.
It is not people who are not willing to talk about this cost, but rather data broker lobbyists, who try to sweep this cost (data protection) under the rug who do not want to talk about this cost. Every time someone makes a counterpoint against broad statements protecting data broker interests (e.g. personalized-ad supported websites cannot exist profitably), that is the debate you are looking for.
This is actually not true.
If I understand your example correctly, you refer purely to the point of view of a citizen, not a company. In that case, I think you are right. It has drawbacks for those citizens that also benefit from it. This was considered when the regulation was created, and some balance resulted.
I think the basic problem is that GDPR is one of those "global" laws - everyone has to follow it, everywhere. This is similar to what the US has (effectively) been doing for a while, perhaps the reason why it became similar. Either way, I consider it as wrong. No law should go beyond a country's border, unless a separate agreement between countries was made. From my point of view, it would suffice to force European companies to not use any services by those who do not comply.
The Abmahnwesen never dies.
https://time.com/5290043/nazi-history-eu-data-privacy-gdpr/?...
Not only did none of us live during the Nazi-Era, but most of us that lived at least during the Stasi-Era (in the West) are routinely falling short of living up to their own moral standards.
They champion getting rid off tax-privacy, they champion getting rid off non-digital currency, they champion blocking social-networks because of "foreign desinformation" (i.e. domestic opposition), they take no offense that a think-tank owned for-profit media-conglomerate does the domestic deletion and blocking of social media accounts (Bertelsmann > Arvato -> FB/Twitter/…).
And most hilariously, progressive luminaries like Daniel Cohn-Bendit or Volker Beck – which during the 1980s gained political traction by "fighting" against having A NATIONAL CENSUS AT ALL – are nowadays championing throwing out medical-data privacy alltogether and having to hand out your unlocked phone to the police at their whim.
(Needless to say how cultural chest-pounding thouse luminaries were in the 1980s)
Can you provide some sources for that, I haven't closely followed German politics in recent years (as I've been living overseas), but I'm quite surprised that DCB would champion police search powers like that.
It leads to some funny statements, to be sure. The woman who said she felt like Sophie Scholl because she had been in coronavirus lockdown was one example - but honestly, if you mess with somebody's parking place, they're about two sentences away from saying you're literally the NS-diktatur.
Still, if it leads to a sense of urgency over privacy, I'm all for it.
Do we actually have any proof of this, over the past years?
Most of these legislation are a big hurdle for startups (e.g. you have to have a "chief privacy officer" for GDPR) but at best a hiccup for big tech (no, million, even billion dollar fines are nothing but a hiccup to their uninterrupted business models).
I am a consultant. My colleagues and I work for a number of smaller and larger companies in the Nordic countries and elsewhere.
My feeling is this isn't as big a problem as HN makes it out to be.
As a small company it seems you'll get questions and free advice first, and then only you'll get fined unless the violation is intentional or so severe that you should have realized.
I guess that it is much bigger problem for the megacorportations. I guess in addition to the fines doled out so far they've also spent countless hours both at work and at night to try to get passed GDPR, and also I guess it has slowed down internal processes quite a bit just like the Sarbanes-Oxley Act (SOX) did a couple of decades ago.
Is this even true for any european country? Don't get me wrong, this is vastly applies right now and the only problems appear at a high level, but If i'm not mistaken no european country has a fundamental text that protects what you're talking about.
https://news.ycombinator.com/item?id=28500092
https://twitter.com/troyhunt/status/970826671300468738?lang=...
It takes less than two seconds for them to save the config but they stretch it to a minute to get people to close the dialogue
Consent about data processing can be done by third parties as a service, but not in the simplistic fashion that is currently in use. It would have to be moved to the first-party, i.e. have the third-party cookie service provider develop a solution that is then deployed by the first-party company itself.
Cookie banners that seek to improve privacy for users by limiting what third parties can do have become another way to track people. Limiting the activity of cookie banner providers would not be a terrible idea.
This consideration is key, even when Akamai servers are hosted in the EU.
Is the fix as easy as that Akamai creating a subsidiary in the EU?
I am in the EU and use AWS a lot, but I am not a customer of Amazon Inc. Instead, it sees this on the bill as who is the seller: "Amazon Web Services EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg".
This is why at some point (I am not sure if this is still the case), the Azure cloud in Germany was fully owned and operated by Deutsche Telekom. Microsoft was basically providing software, consulting and brand. This way, it was legally not possible for Microsoft to access the data.
The article has "Importantly, the Wiesbaden court appeared to accept that Akamai may have stored Cookiebot data on EU servers, and not in the U.S., which suggests Cookiebot’s agreement is with Akamai’s German affiliate."
I am sure people here will find at least 20 solutions on the problem on "how can a group of evil websites track a user across if cookies do not work but JS is On", the solution would involve something like drop this lines in your html page and the js code there will connect to some server and store some fingerprint there, Google might decide to give your browser a fingerprint to help with their ad business.
[1] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
(Not a lawyer)
Not all, websites, though; I believe medium, of all websites, will actually not embed some content if you sent it a DNT header. Not sure if they still do that, though, because their UX for readers has become absolute trash.
We don't see many websites who opt out out of the "track the users all across the web" scheme in order to remove the cookie banners altogether.
On the other hand, thanks to the banner everyone has become aware that the are being tracked. This is good because it brings people into the discussion, so that when EU says "stop tracking" people are not puzzled about what tracking those Eurocrats are talking about. How people are supposed to know if they should support the actions of their government if they don't know what's happening behind the scenes?
Cookies are entirely on the client side anyway: trusting every website to do the right thing is obviously not going to work.
What we need is a low that forces websites to obey the "do not track" header.
If you take the article at face value, it is illegal to create any kind of TCP/IP connection with a server that is operated by a company which does not operate exclusively in the EU.
This is a strong interpretation, but it‘s really not far off from what the court did here: they declared it illegal that an IP Adress (!) was transmitted (not stored?) to a company that could potentially (?) be subject to non EU subpoenas.
If NOYB managed to make the entire internet illegal just so they have a sharp axe to go after the things they don‘t like (Google Analytics, cookie "consent" banners), congratulations. They have built a slope so slippery it should have an ICU at the bottom.
In my view there is no crime bad enough that it justifies having laws on the books that criminalize everyone just so we can selectively enforce them against the bad ones.
It may be worth noting that this doesn‘t involve a fine, only that they cease the activity. That is my personal silver lining as someone operating services within the EU that clearly are not lawful.
It‘s literally a scorched earth, because it will be pretty tricky to provide even gopher services to a global internet until we develop a TOR like alternative to TCP/IP.
In my view there is no crime bad enough that it justifies having laws on the books that criminalize everyone just so we can selectively enforce them against the bad ones.
If so, that's my point. As far as I understand what Akamai does, they where probably just the conduit for establishing a TCP/IP connection to the Cookiebot service. The court neither felt the need to establish that Akamai stored the data, nor that it left the EU. The mere fact a non-EU company was involved in the connection was enough. I'm probably wrong, and I would like to know how, to maintain my sanity.
You mean an ISP? No, Akamai isn't an ISP.
Cookiebot is unambiguously using its own trustworthiness to let Akami access their users' personal data. There's nothing fuzzy or dubious here.
The only news is that what many people expected to be perfectly legal, that is doing that with a confidentiality clause and never having the data leave the EU actually wasn't, because of a different detail.
If I serve images from Akamai (or Cloudinary, FileStack…). Do you think that‘s problematic?
Do you think apple is is deceiving me when I download a song from iTunes?
That's fine if you ask me. If you can't understand that popup, the site is user hostile and you shouldn't give them your business.
It made me a proponent of leaving the EU. Not because I don't think European unity would be beneficial, but because the current implementation is deeply faulty and little more than a convenient scapegoat of national governments pushing through changes they are too afraid of doing at home without democratic oversight.
Google analytics is going to be essentially outlawed in the EU.
Hosting with any company with a US presence is going to be questionable. No Aws, Google Cloud, Digital Ocean, linode, azure, hetzner… (Leading to the further question of who you can host with — what big EU cloud providers are there without a us presence)
I’m not sure where that leaves the EU, other than possibly hardware in a local data center.
Similarly with OVH. A client is working on migrating stuff to OVH, because they felt confident enough that US employees of OVH would have to easy access to EU data. Then staff at OVH in the US takes down all of OVH for a few hours on a monday, that have made them reconsider.
edit: NVM I see your point now, that having any US presence is a problem (and Hetzner has a US datacenter too).
So this would probably require massive company fragmentation/restructuring to potentially stay compliant?
Really curious how this is gonna turn out.
Might be a viable option for smaller players.
One can only hope.
The needless dispersion of your users’ browsing history is in itself disrespectful. Yes, privacy regulation do make life complicated if you choose to ignore their core, and instead create some Frankensteinian caricature of an infrastructure to continue doing business exactly as before.
Yes, 100%, it is relatively easy to just not track your ~~victims~~ customers every move.
If that develops further, people will be forbidden to store data outside of their country, so that the data can always be requested by local agencies.
But like OP (I assume) I have the privilege to live in a society where, every few years, I have the opportunity to elect our leaders and discussion about laws happens in the public and needs to find a majority in parliament. In the EU my country has a voice and our elected representatives help shape the directives and regulations.
While the US is also a democracy, I don't have any influence there at all (which is fine) and my data is foreign and is treated differently than that of US citizens. Furthermore, even if an American company does something blatantly illegal my practical recourses are severely limited by costs and distance (try suing someone in California)
I am not ready to accept that when interacting with a local business any data needs to flow across the Atlantic.
I really like the idea of having a local independent data handler who operates European infrastructure on behalf of companies like Microsoft did a few years back.
It's not, users can of course consent to data being stored elsewhere. The article explicitely points this out:
> Instead, the court took the approach that data could only be lawfully transferred to the U.S. via a mutual legal assistance treaty (Article 48 GDPR), or under Article 49 GDPR’s derogations, such as consent. It confined its lawfulness analysis to those grounds alone.
The only viable solution would be for the EU and USA to come to an agreement that guarantees privacy for citizens of either jurisdiction. So far, nothing of the sort has been accomplished because the US does not like to give up their power over US companies; I can't say I wouldn't do the same in their position.
Instead, EU websites will now be forced to buy their cookie management from EU providers who adhere to EU privacy laws. So in effect, they are merely putting more of the spirit of the GDPR into laws.
And for US providers, they can always open up a local EU subsidy, implement the relevant regulations, and then sell their service to EU customers again. So this is specifically to allow people to circumvent the EU rules by using "I'm an US provider" as an excuse.
Also, I like how they called out that transmitting the visitor's IP and referrer URL to a US service might enable them to build a profile which would be legal under US law and illegal under EU law. That's why they now block the transfer of the visitor's information out of the EU in the first place.
This is simply false. Cookiebot is an EU provider. They're a danish company.
The ruling is about providers not being able to use CDNs that are subsidaries of US companies, e.g. Akamai, Cloudflare, AWS, Azure.
As a (EU) user, I hate all cookie management popups. And those aren't brought by evil US companies. They a forced by dumb law that tries to "protect" me. This law specifically mentions that I need to be nagged for every single new domain I visit (dozens per day) and specifically mentions that having a single setting I can tweak is not OK.
The amount of thought that has gone in the law to ensure that people are nagged on every. single. page. they. visit. and. that. there. is. no. way. to. shortcut. this. boring. and. useless. process. is maddening...
There is a way to shortcut this: Do-Not-Track header. But nobody follows it. There is also GPC (https://globalprivacycontrol.github.io/gpc-spec/) but browsers need to implement it. There are also several other ad-hoc ways of shortcutting it, like third-party cookies, for example. But that cookie would only allow "shortcutting" the "no" answer, not the "yes". So companies simply don't implement it.
There is also the possibility of not tracking at all. So the ball is entirely on the businesses' court.
The law is fine actually. The only issue is that it's not strict enough.
This is false, automated refusal (or consent, if one swings that way) of tracking exists. https://addons.mozilla.org/firefox/addon/consent-o-matic/ https://github.com/cavi-au/Consent-O-Matic
> This law specifically mentions that I need to be nagged for every single new domain I visit (dozens per day) and specifically mentions that having a single setting I can tweak is not OK.
This is also false. But humour me, where in the law does it say that? Concrete citation, please.
No it does not.
The company behind the website decided that nagging you is worth it to get your data. They have the very simple option to not track you and provide a better user experience, save you data, save you battery power, save you time and respect you. They don't.
Sidenote: I did laugh at "dozens", I'd urge you to keep count for a day or two. If true you are a strong outlier.
The cookie management pop up here was Danish. The problem was that they were using (the German affiliate of) Akamai for their CDN.
The CLOUD act is built on the presumption that non-americans don't have the right to privacy, and so it includes language to the effect of "you must provide data that you or your subsidiaries have access to".
This means Akamai storing data on EU servers is not sufficient (Akamai has access to the data), nor is an EU-based Akamai subsidiary sufficient because the US parent company is required to pass data from their subsidiaries to the US gov.
This is a direct result not of EU over-regulation (which I'll admit, they love), but the US government deciding that every company that works overseas should be an extension of their intelligence services.
"Per the Court of Justice of the European Union, IP addresses are personal data (the court also considered Cookiebot’s “user key” to be personal data)."
They seem to be using the term personal data (correctly) but I cannot help but sense some disdain for it in the writing as if the writer was still thinking personal data being PII (which it's not). A 5-star rating I give a driver is also personal data because it generated by me or obtained from me (and that's why you can get it when you request an export of your data under GDPR). But then the article goes on to nitpick on the definitions: "Because the Wiesbaden court cited the CLOUD Act as a reason to limit U.S.-based services, we note that the claim for “any US connection” is incorrect, because the CLOUD Act only applies under U.S. law where there is possession, custody, or control in the U.S." Possession, custody, or control pretty much covers everything when it comes to cloud computing infra.
"NOYB has filed over 100 complaints alleging improper transfers to the U.S., for a range of data analytics and cookie plug-ins that are pervasive in the current online ecosystem."
I am a happy supporter of NOYB and glad to see my donation being used well. Though I am a bit worried about being able to use Cloudflare in the future.
There are a bunch of details to work out (i.e. what should be the default setting, will this be an HTTP header or some API, what granularity, etc) but I'm sure the end result will be far more beneficial to society than a zillion companies each implementing their own cookie handling logic and researching their own compliance.
And I say this as a free market liberal who is skeptical of government intervention.
Not touching PII (as defined by german courts) with a ten feet pole seems like the only reasonable course of action for a company without a legal department.
In that case, that new email-address will also be considered PII as it's linked to you if I'm not mistaken.
The problem is stretching the definition of PII beyond it‘s breaking point to include shortened (!) IP addresses, anonymous identifiers and fingerprintable http headers. Now this forbids the transmission, not the storage, of such data. What‘s even the point anymore?
In the US, what is generally regulated is "posession" of data, with narrow definitions of what PII is and no restrictions on anything that isn't. In GDPR, what is regulated instead is the possible justifications for processing of that data.
For example, (IANAL caveat aside, speak to an actual privacy lawyer) it is fine for me to store full, unredacted IP addresses in my access logs for diagnostic purposes.
However I, for example:
- have to be able to provide information on what is stored and under what justification
- have to provide information on who that data is transmitted to
- have to be able to show an authority it is really necessary for me to store this data unredacted
- must put in place adequate measures to protect it
- am liable for exposure of that data
and may not:
- store the data longer than necessary
- use that data for other reasons, such as marketing
- transmit that data to a third party unless it is contractually bound to the same restrictions as me
When something is personal information, the only thing that means is that it is illegal to not have a justification for processing or storing it.
So for your example, processing headers is fine, fingerprinting headers is probably not. Recording shortened ip addresses is fine, unnecessarily sending them to the US is probably not. Anonymous identifiers are fine, tracking people with them is probably not, etc.
In my privacy policies, I try to follow what I think is the spirit of the law and hope/pray for the best. I list point for point what data I use, why and to what third party tools I send it. That's like 2 sentences per point. I have never checked with a lawyer and don't copy and paste any legalese like everyone else seems to do. After reading through the court decision here, I'm almost certain that what I do, and how much I explain it, is not legally acceptable, but I feel fine about it.
I don't get why the article is so whiny about the court holding the US companies liable for the permissions the US government gave itself.
The US has assumed jurisdiction and is trying / has succeeded ("legally") to kidnap people extraterritorially for decades now - Kim Dotcom, Julian Assange, Alexandra Elbakyan, a whole lot of Russian hackers that had been fake-invited to security conferences or job interviews: none of them has committed crimes on US soil or in an US territory, and yet the US is still trying to get people deported to the US so that they can be tried by the regime. The US government heaps piles of dung upon sovereignty of other countries. The US mega-corporations ignore tax laws wherever they can while destroying local markets with price dumping only affordable because of immense amounts of pension fund money being poured into venture capital. US advertising giants act like European legislation doesn't even affect them. The US threatened to sanction a German harbor for providing services to ships building North Stream 2 (not that I like that project very much, quite to the contrary, but nevertheless it is a disturbing overreach!).
The EU is now beginning to assume the US and any entities based in it cannot be trusted for all of these reasons (even if no one says it in the open), and suddenly all the tech companies cry and complain. All I have to say is, the US is at fault here. You made your bed, now sleep in it. Or redirect some of the lobbying budget to campaigns of politicians willing to end the madness.
Is this still true? When ERISA was amended/relaxed and most pensions were defined benefits it was probably true.
But aren't the vast majority of pension plans defined contribution now? Are defined contribution plans being funneled into venture capital (is that even allowed?)
Certainly social security money is not -- they're required to invest that in US treasuries.
At least according to [1] about 20% of VC funding came from pension funds, and per [2] about 10% of pension fund assets are invested in "private equity". Given that we're talking about ~ 35 trillion US-$ in total pension fund assets [3], it's safe to say that it is an immense amount of money.
And by the way, it's not just the startup/VC market that is being completely undermined by dumb pension fund money from the US. Real estate across the world is bought up by pension funds, driving up prices - good for those who sell to the pension funds, bad for those wishing to obtain their own home or renting.
The way US pensions are set up is fucking over the entire world.
[1]: https://www.ipe.com/letter-from-the-us-pensions-and-start-up...
[2]: https://www.pionline.com/interactive/private-equity-returns-...
[3]: https://www.statista.com/statistics/421729/pension-funds-ass...
It would be absolutely asinine to assume that a layman could understand, much less implement the currently available solutions in an effective manner, so here are the two scenarios that small businesses are faced with:
a) They still wanna make use of cookie powered tech and just do it without consent, which opens them up to legal trouble
b) They don't do it and give up on functionality, which big biz will be able to provide, putting them at a disadvantage and making the web less democratic in the process once again.
While I have no particular thoughts about the type of providers targeted here, I am certain that the last thing the current setup needs is additional complication.
Everything tech and privacy is pretty easy looking from the HN ivory tower. Meanwhile half the world runs WP installations that date back to 2016 and can't change a paragraph on their "about us" page without contacting "the web guy".
I don't think small businesses typically run targeted ads on their own websites.
To be clear, NOYB allows 60 days after notification for removal (instead of 30 allowed by the law) before complaining to the national data protection agency and even then agencies rarely give out serious fines if you are ready to comply and did not grossly misuse the data, at least in Sweden: https://www.enforcementtracker.com.
[1] In fact, I try to use a lot of services without consent while providing my personal data. The trick is that I want to ensure it will ONLY be processed for a legitimate business need.
Amazon is always going to find a way to work within the limits of whatever the EU throws at them. Begrudgingly, certainly, but eventually in strides, and with the confidence that an army of lawyers and other smart people does offer. They can even willingly chose to work outside of it, because heck, breaking the law is just another business expense.
Your typical local mom and pop store is likely unaware of what the boundaries are, where they are, what it all means, how to implement any of it. They are mostly looking in horror at the incomprehensible monster that is GDPR.
The point being: Restrictions on SaaS solutions are not gonna hit Amazon. Amazon does not need a SaaS cookie banner. They can have their own team that does nothing but build well tailored cookie banners for any country in the world and update them daily to whatever standards are required today.
Alas, a small business can not. The rules are the same, and thus the burden is distributed incredibly unfairly.
Does this mean that for those of us that manage our own cookie banner and overall website in Cloudflare (also US company) will have the same issue? And be deemed unlawful?
"Cookie Banner" is an industry term, which is incorrect.
Yes that's the sad thing, they do not need cookies anymore.
CookieBot are probably one of the better CMP's I've used, but I'm surprised they haven't yet implemented full EU isolation - which surely is the short term solution here. Fathom have written extensively about their work on EU isolation which I think is very relevant here https://usefathom.com/features/eu-isolation
Using these automated services that pretend to "automatically" block various categories of cookies is also a ripoof. They use simple keyword searches and similar to try to establish whether a specific script is used for statistics, preferences, etc.
A properly implemented banner (i.e. hand-crafted for the site, and obviously updated each time any script is updated) would be pretty expensive to create and maintain. But if one doesn't see that as one of the key purposes of the law (i.e. push web sites towards using fewer of them because the technological and legal overhead is costlier than whatever the gain is) then I think it's being read a bit naively.
However, CookieBot is terrible imho. They delay page load by about a second (!) because their APIs are so slow. Their tech is incredibly fragile, if their crawler has an issue and doesn't crawl your page completely, they'll silently (!) remove all cookies from the consent and leave you completely non-compliant until the next successful crawl (crawls take hours to days and are automatically done once a month). Their support has a response time of 3-5 business days (!) for commercial users and consists of people who barely know the product and definitely don't know anything about web tech.
I don't have a favorite vendor in that market, but CookieBot is definitely the worst one I have worked with.
The right to informational self-determination would not be compatible with a social order and a legal order enabling it in which citizens can no longer know who knows what, when and on what occasion about them. Those who are uncertain whether deviant behaviour will be noted at any time and permanently stored, used or passed on as information will try not to attract attention through such behaviour. [...] This would not only impair the individual's chances of development, but also the common good, because self-determination is an elementary functional condition of a free democratic community based on the ability of its citizens to act and participate. It follows from this: Under the modern conditions of data processing, the free development of the personality presupposes the protection of the individual against unlimited collection, storage, use and disclosure of his or her personal data. This protection is therefore encompassed by the fundamental right of Article 2 (1) in conjunction with Article 1 (1) of the Basic Law. In this respect, the fundamental right guarantees the individual's right to determine for himself or herself the disclosure and use of his or her personal data.
Sorry, I couldn't resist.
What do people get as benefit from all this irrelevant madness? Do people think they are really not being tracked or their communications not spied? And, has it helped european tech in a way that i have missed?
I imagine most people think that the companies doing the spying will get a nice fine in the near future. I don't think anybody believes there's no spying, even more because the law also made the spying quite explicit.
> And, has it helped european tech in a way that i have missed?
I also imagine most believe it has helped European people. I'm not even one and I believe it has helped me.
(Not a lawyer)
If we do vaccine passports, can we just stop the whole data protection charade completely?
On an even more fundamental level this is a conflict between American legal system of common law vs European statutory legal system.
On other hand, there's encryption regulation and absurd piracy strictness.
Please someone with a formed perspective tell what's happening? What is a general vector of European policy on the internet?
Could you give an example of an EU regulation which actually restricts encryption? There have certainly been discussions about adding backdoors to encryption (as is typical for any jurisdiction that doesn't have them), but my understanding is that these proposals have reached a dead end. Here's an update from last week:
> The lead committee for the internal market and consumer protection (IMCO) in the EU Parliament spoke out on Monday evening with a large majority with its current position on the planned Digital Services Act (DSA). ... It also includes the right to end-to-end encryption. “The member states must not prevent providers of switching services from offering end-to-end encrypted services,” demanded the representatives. This is essential for trust in the network and cybersecurity.
https://marketresearchtelecast.com/digital-basic-law-eu-mps-...
I do not think I really qualify but hey.
> What is a general vector of European policy on the internet?
Generally the EU is very pro-privacy but sadly companies like Facebook bribe our "data protection officers" (sorry idk how to translate) and individual EU countries also just break the EU law on a regular.
And they're not very good at their job (or maybe they are, if you're Facebook): https://www.euractiv.com/section/data-protection/news/irelan...
I was building a simple website for my team recently and the biggest problem I had was ensuring the compliance of cookies - I had to spend days reading through all kinds of laws and regulations only to eventually end up going through a "Cookie Policy Generator" which produced a 10-page legal text that I dont understand. Apparently I'm not the only one since there are a lot of business that offer "cookie policy management" as a service for companies. Here is the generator if anyone wants to try it out for themselves: https://www.activemind.de/datenschutz/generatoren/datenschut...
We do see companies assessing whether certain cookies are actually needed, e.g. Cloudflare[0]. Also products advertise themselves as cookie-free[1]. That probably wouldn‘t have happened without legislation adding a lot of friction to having cookies.
0: https://blog.cloudflare.com/deprecating-cfduid-cookie/ 1: https://plausible.io/
You can totally make a simple website with zero legalese and no cookie popups.
In short: you shouldn't track the user, unless the user opts into it. Cookies are one of the many ways that can be used for tracking.
There are other regulation pertaining to data retention, processing, etc. But since you focus on cookies, that's the gist of it.
You don't have to ask permission to deposit a login cookie, since that's functional and non-tracking. Using that cookie to track across websites requires consent. Depositing a Google Analytics cookie requires consent.
Any website that shows me a cookie popup screams "we want to track you! We collect data on your online behavior and sell it to third parties!"
About your strugglings, cookie compliance is extremely simple if you plan to not track your users. Technical cookies for sessions and application states are allowed without requesting user consent. So just respect your users.
As a user ? No. As a business ? I brought additional costs and risks, but didn't change anything in the data we collect. But some pencil pusher is convinced he made the world a better place, so there is that.
Those companies exist solely to prey on people who can't find their way to a site like gdpr.eu
Let me give you all of the law you couldn't understand in simple statements:
1. you don't track your users by default. period. no consent is needed
2. you need to store some data about a user because that is crucial to the core functionality of the website (e.g., keep user logged in, keep a user's shopping cart etc.), then you can use those cookies, and those cookies alone, for that functionality, and that functionality alone.
2.2. Do not store personally identifiable data. If you do, you're liable for protecting and not leaking it. When a user requests this, you must delete al of that user's data
3. For literally everything else you have to ask the user's consent.
If you were actually building a simple website, you could've stopped at 1.
But then I thought to add a 'cookie consent' banner anyway because people expect one.