Consent-O-Matic: Automatic handling of GDPR consent forms
github.com
github.com
It could even just be a flag in the cookie itself declaring that something isn't strictly necessary.
The problem is, that consent must be given freely and fully informed. And this is the catch. Automatic acceptance isn't fully informed and with that the consent isn't valid.
So it would put the companies in danger and therefore no company could honor this standard.
Sadly - as it would make live more easy. But it would be enough if companies would just not use dark patterns. If there is a banner the "Accept all" and the "Deny all" must be both be the same level of "easy-ness" and the same amounts of clicks (and wait time). Only if you want to you would need to dive into the detailed categories.
And even there: Most sites abuse "legitimate interest". Everything non essential should by default be inactive. But sadly it isn't.
Disclaimer: I am a data analyst/Web analyst. I do this stuff for a living for clients. Still I value these things highly. And would love for it to be implemented correctly.
Non-essential cookies could be enabled via a configuration menu opened by the user at a time of their choosing. But everybody knows no user is going to do that, particularly unprompted. So they create a pop-up banner to do both the prompting and the configuration.
And everybody knows most users, when they see a pop-up, are just looking for the sequence of button presses needed to remove the pop-up. So they make sure that that's "enable all cookies" because they know if it's "only enable essential cookies" vanishingly few users will enable non-essentials. Why would they?
If everything non-essential were required to be inactive by default I think the pop-ups would disappear entirely. There'd be no point to them because vanishingly few users would ever change the defaults.
According to the GDPR, all non-essential tracking should be off by default, so "decline" is already the default if companies were compliant with the regulation (which is a big "if").
Left the code in anyway but that’s the thing about these things: consumer behavior reveals that they don’t actually give a fuck about whether anyone obeys this or not except for the time when they want to be outraged.
Then the browser could take care of displaying it in a uniform way together with the “accept” and “reject” buttons in a uniform way.
Would be much easier for the website and it would make it impossible to use dark patterns.
By pretending that advertisement and tracking are part of Legitimate Interest, and having a "secondary section" that is not only pre-accepted, but also overrides the proper consent part.
To really decline consent in those cases, you must uncheck all "Legitimate Interest" checkboxes. Not only those things are not legitimate interest, this also overrides the lack-of-consent provided by users for a couple vendors.
Legitimate interest is not a get out of jail free card. You can't apply it to everything and pretend you got consent.
The full list of the LI purposes claimed by adtech players is available at [0]
As for why they're enabled by default... I'd imagine there's a legal reason. GDPR doesn't just apply to adtech, it's everything.
In any case, it's not sites that are the issue. It's the CMP screens.
I never said the opposite and never said that was problem. Presenting non-Legitimate Interest as if it were, however is shady and probably illegal.
> The user's choices for each Legal Basis are sent separately in the TCF consent strings and entities are expected to adhere to these rules.
I never said that being separated is a problem. The problem is using anything that is firmly NOT in the Legitimate interest camp as if it were, and using that to mislead customers.
> One does not override the other.
It does in this case, and it is easily verifiable. Even if I disallow a certain tracking vendor, it will still load stuff from this vendor in websites, even though nothing from this vendor configures "Legitimate Interest". And all my data will still be piped to those adware, etc, vendors, that provide no functions other than adware, tracking and other shady stuff that GDPR requires consent for.
> As for why they're enabled by default... I'd imagine there's a legal reason. GDPR doesn't just apply to adtech, it's everything.*
That's beside the point. If it were really Legitimate Interest, there would be no need for asking.
Just as writing and running an install script with --accept-tos is valid.
A court would look at this and a person who mindlessly clicked "accept all" on every website as equivalent.
Browsers could propose an API for this functionality and no doubt some websites would implement it. They havent but they could.
Whether there's any point is another question. Websites would probably rather use dark patterns to get us to click accept all, so any API that went beyond accept all and allowed a standardized user policy on data collection would have a limited uptake.
IANAL so it's pointless for me to argue on that point. Of course if somebody is happy to accept in advance any privacy policy and will confirm all of those automated choices in a court (if they'll ever be challenged, can't think why), no problem with that.
My point was that we shouldn't expect a major browser vendor to go through all the process to build an API with those legal implications. I wouldn't bet on major websites adopting that API anyway. It looks so much following the letter of the law and circumventing the spirit of it. Very risky, both legally and as a middle finger to the regulators.
I dont think this is true either. The consent options would typically come under a few pretty well defined headers (e.g. advertising) and could include the capability of raising specific exceptions for nonstandard requests.
A feature saving 2 seconds on 90% of sites is a big deal.
In the same way, GDPR requires informed consent about the specific use of data by a specific data controller. From https://gdpr-info.eu/issues/consent/ :
> For consent to be informed and specific, the data subject must at least be notified about the controller’s identity, what kind of data will be processed, how it will be used and the purpose of the processing operations as a safeguard against ‘function creep’.
The proposed browser-based solution that sends an automated acceptance on behalf of the user would not qualify as informed consent in the context of the GDPR, because the consent was given prior to the human being informed about the specific use by the specific site.
Medical consent is a whole different kettle of fish and I may be off base here but I am pretty sure you can preauthorize consent for, e.g. theres a risk you may become unconscious and need follow up treatment.
>The proposed browser-based solution that sends an automated acceptance on behalf of the user would not qualify as informed consent
It's absolutely possible to have all of this information sent in an API to software acting on behalf of the user. The user has been informed and the obligations of the website will have been discharged. What the users browser does with this is the users business.
That road leads to banning street photography and CCTV, and being able to get a gag order to stop people from saying "Yeah I saw Brian at the bar last night". When does it stop?
There are no uses of cookies an average user cares about that aren't already illegal.
They are basically all for the same thing, to spy on you and sell your data to third parties to the fullest extent of the law, excluding any data you would actually notice being sold like credit card numbers, and many users don't care.
* Asking if somebody saw Brian at the bar last night is acceptable. Asking everybody if they saw Brian somewhere is acceptable in limited circumstances, such as Brian having been kidnapped. Asking everybody to list out who they saw and when is an unacceptable violation of privacy.
* Street photography is acceptable. Taking a picture once every day of the same house may be acceptable, such as if it is a historically interesting building, or if it is your own house. Collecting millions of street photographs, along with the time they were taken and who was in each photograph, is an unacceptable violation of privacy.
* CCTV is acceptable. Maintaining records of CCTV indefinitely may be acceptable, depending on the type of building. (e.g. The Pentagon may be justified in keeping CCTV recordings indefinitely, but the local laundromat is not.) Linking CCTV cameras together into a centralized query-able network that tracks people between locations is an unacceptable violation of privacy.
There are two common features that I realized in these examples. First, even if an individual action is acceptable and justified, repetition and coordination of that action may not be. This is similar to how saying hello when crossing paths with somebody is a courtesy and a pleasantry, but saying hello to the same person every 30 seconds is stalking. The difference in scale produces a different in outcome.
Second, there exist gradations of privacy, rather than being a binary divide between public and private spaces. Between a completely private space, such as a person inside their own home with the windows drawn, and a completely public space, such as a person giving a speech on live TV, there are intermediate spaces. A person who is walking down the street has partial privacy, where their actions may be remembered by passersby for a day or two, but wouldn't be remembered a month or a year later. In the past, these gradations of privacy were maintained by the limits of human memory and the high cost of technological memory, but the cost of technological memory has fallen to a point where this social construct is breaking down.
Summing up, I would say that we cannot have a modern technological society if we *don't* treat tracking with the same concern we treat medical consent.
Install scripts run with --accept-tos have nothing to do with personal data or privacy, and are outside the scope of GDPR.
They're treating "Accept cookies" with the same seriousness you'd expect from "Do you consent to me putting a whole package of cookie dough up your rear".
The whole GDPR seems to be one step away from censorship. And it seems almost like the real intent has less to do with user choice and informed consent, and more to do with just trying to kill off data collection as a business model completely, before we have a replacement for it.
"Accept all" and the "Deny all" must be both
be the same level of "easy-ness"
I think this is not clear until it has been tested in court.Many websites now have two offers: Free with 3rd part ads and paid.
Surely paying is much less easy than clicking "Ok, show me the content with 3rd party ads".
It will be very interesting, how courts see this.
The current situation is, that the courts decided, that the business model (advertising and by that tracking the sh*t out of people) is valid if they offer an alternative were people pay them for access to the content.
were already in court
Really? That surprises me. I did not hear about this.Do you have a link to such a case?
Sorry.
The really problem is enforcement has been lacking, this is what NOYB are co. are working to fix.
https://gdpr-info.eu/art-7-gdpr/
I don't think it means that when asked for consent, the user must have an easy way to deny that consent. As the user can always decide to simply not use the website.
It was very ineffective.
Something similar but actually enforced (easier said than done) and utilized would be very nice indeed.
There is a misconception, they don't want it do be convenient, the all purpose is to as annoying as possible and legal, to force you to use the easy allow-all-path. So even if there is an API they won't use it. They don't want to give you a choice, they want that you to allows all access.
Even with a deny all feature, they will use it if it's legally mandated, since apparently that's how we handle privacy now
There was: https://en.wikipedia.org/wiki/P3P
AdTech companies want to track you, and it's naive to think they will ever honestly and voluntarily use any APIs that blocks it.
Current deliberately-awful cookie consent prompts are malicious compliance aimed to make law makers look incompetent and make people resent privacy protection laws.
The context has obviously changed: there used to be no consequences for lying/bypassing (I didn't actually know about the Google case you mention; although it doesn't surprise me!), and most importantly: there were no consequences for not bothering to put it on a site at all. Hence the low adoption, and hence it died away. That's now changed, there's a chance some "non evil" sites might bring it back.
> Current deliberately-awful cookie consent prompts are malicious compliance aimed to make law makers look incompetent and make people resent privacy protection laws.
Yep. That's why machine-readable requests, with default-deny responses from user agents, won't appear any time soon; especially in browsers made/sponsored by adtech giants! The inconvenient, manual-effort is a feature of consent popups (at least, for those who came up with the idea; most sites just jumped on the band-wagon)
If the number of people who would use "Deny all nonessential" is less than the number of people who currently deny consent, it's a win for them.
I remember 20 odd years ago now when Firefox came out with a popup blocker standard, built-in. Whatever happened to this "we need to reduce annoyances on the internet" movement? Why aren't the browsers themselves doing more against it?
I mean I know that Chrome and Firefox won't block ads by default because it affects their bottom line (Chrome through Google ads, Firefox through Google money), but what about GDPR consent forms and newsletter sign-up popups?
There was Do-Not-Track, but the industry decided it shouldn't be respected.
Grandparent post asked for a technical solution to hide cookie banners forever.
A websites don't have to show any cookie banner whatsoever if they honor Do-Not-Track.
If they don't show a banner but still track, they're breaking the law.
The problem of cookie banners is easy to solve. All that's lacking is honesty from adware vendors and website operators.
Do-Not-Track can already be honoured by website operators. The issue is just that they choose not to do it.
* https://www.cnil.fr/en/cookies-google-fined-150-million-euro...
GDPR isn't about cookies, it's about collecting, storing and transferring data. Done properly, GDPR notices should allow users to opt in to having data about themselves collected by the interested company (and other things like acknowledging the relationships and responsibilities formed by that consent - like requesting deletion and having it honoured).
We just happen to use cookies to do much of that collection. We also already had "the cookie law", so it seems "pragmatic" to piggy back the two things, for the sake of "user convenience".
GDPR creates responsibilities and guidance on all the database tables, the system designs, the job descriptions and so on which operate around data about people.
/FanboyNZ
Because it inserts a overflow: hidden in <html> or <body>
Quite annoying!
Granted, whether or not sites are following the law is another matter altogether.
Since creating rules is one of the more time consuming parts of maintaining the project, we are happy for any help we can get through pull requests to the rule lists.
See screenshot from config here: https://imgur.com/a/fHfuZ0O
Adsense offers an automatic consent modal. But the problem with that one is that it not only displays the consent modal but also injects a smaller widget into the site. It looks like the widget only pops up when the user scrolls down to the bottom of the page. Unfortunately, that also makes it pop up when the page is not longer than the screen. So pages where all content fits on one screen look really shitty.
Anybody who has a website with Adsense here? How do you guys deal with this?
Anybody here who wrote their own consent modal?
I am about to implement my own. Unfortunately that will then not be automatically handled by extensions like the one in this post or ublock. Putting the burden of clicking it away on my users. Even on the 50% that use an ad blocker anyhow :/
Since advertisers need to know if you really show their ads, the ads need to send some signal back from the user to the advertiser. So ads always send the user's IP to a third party: The advertiser or a trusted intermediary.
Assuming no consent to that for everybody would mean that the revenue of my website goes to zero. And I would not be able to run it anymore. As the ones paying for the costs are the users who consent.
> If you trust prebuilt versions of extensions like this--
> Available on Firefox: https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat...
> Available on Chrome: https://chrome.google.com/webstore/detail/consent-o-matic/md...
Bigger awareness might lead to more contributions to automate away even more consent forms.
If you self host everything, but are still using my personal info, you need my consent.
This applies whether it's you doing the collecting or Google's "free" analytics service.
Of course if you're a running a small website you'll probably get away with it. For now.
EDIT: not to knock on the efforts of this developer though! Just thinking that actually holding websites accountable would be a way out of this internet harassment arms race in the long run.
Where it started not working so well was in conjunction with NoScript (which I've started using recently).
Then on some pages, it stalls, showing a notification while waiting for a consent-dialog to show up, before eventually giving up. But because of NoScript the dialog itself is blocked and will never show up.
In these cases Consent-O-Matic is actually creating a bigger distraction than it needs to.
Would be nice to see that addressed somehow :)
Its mind boggling that anybody would agree to give away their personal data to advertisers in such a blanket fashion.
One problem is that often, those forms insert a "overflow: hidden" into either <body> or <html>, meaning the page cannot scroll anymore. Twitter does this too.
It's possible to just remove it with the dev tools, but it's quite annoying.
I've asked ublock for a way to fix this, like:
##body,html:matches-css(overflow: hidden):style(overflow:auto !important)
But it doesn't really work.
No idea what should have been the effect.
Currently it handles only some consent forms.
Oh and Twitter.
This is by default the quickest way to get to the content. Without compromising privacy by using addons.
So no - advertisers never "see" me.
My understanding is that GDPR concerns how you use PII and contact information and the requirement that you be able to request your data be deleted. So I expected a data removal request form and/or a contact consent form.
0.
Not a single one.
I wish (computer-savvy) people would stop talking about "cookie laws" altogether, since there's no such thing.
When people say "the cookie law", they're usually referring to two EU regulations:
- PECD: https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...
- GDPR: https://en.wikipedia.org/wiki/General_Data_Protection_Regula...
However, neither of these is a "cookie law". In particular:
- The laws cover much more than "cookies"; e.g. they're just as applicable to browser fingerprinting, Flash "supercookies", etc.
- Cookies which perform a requested job have implied consent: users visit an online store because they want to use the shopping cart functionality; if they don't agree to having a shopping cart cookie, they can leave the online store. (In contrast, users don't visit online stores in order to be tracked by advertisers; so separate, explicit consent is required)
The follow-up privacy legislation also bans the current dark pattern of making the "accept all" button more prominent and obvious than "decline all" at least requiring both to be equally prominent. The flow of having to go through "manage" or "see options" or other shenanigans as links in order to decline all has always been in violation of the GDPR and could theoretically open you up to the fines as it demonstrates intent.
"But we want to show you ads to finance our website and our advertising partners want to abuse your privacy" is not a legitimate interest.
Informed consent about cookies was a law that predated the GDPR.
The consent boxes only got worse because, with GDPR, you suddenly have regulators who care about these things and are empowered to impose hefty fines. So people stopped ignoring the whole space of privacy, as they had been before.
One of the declared goals of GDPR is to reign in "profiling". So the industry started trying to desparately weave a narrative on the grounds of consent: they wanted to create an electronic paper trail that would somehow support their claim that people were consenting under the rules of the GDPR to being profiled.
But consent under the definition of the old cookie directive does not meet the standard required under the GDPR for consenting to profiling [1]. People like Max Schrems are actively engaged in trying to get the industry to turn away from their noncompliant ways [2]. Especially the use of certain UI dark patterns has already lead to hefty fines [3].
My hope is that, when this has all played out through the legal system, it will become clear to the industry that the stuff they are trying to get you to consent for them to do, is just outlawed altogether, thus scoring a victory for privacy on the web and rendering that consent-stuff moot.
If not, regulators may need to get involved to make it more clear, that this is the intended outcome, which I have no doubt they eventually will.
I also have high hopes that, eventually, GPC will become enshrined in law [4]
[1] https://academic.oup.com/idpl/article/5/3/163/730611?login=f...
[2] https://www.dataprotectionreport.com/2021/06/max-schrems-pri...
[3] https://www.cnil.fr/en/cookies-cnil-fines-google-total-150-m...
Or even better, make the form automatically recognizable by your browser and a setting in the browser so that it says yes or no for you.
Have you ever notices that the "yes I agree" button is most of the time MUCH easier to click on than to tell "no I don't" ?
That's illegal under GDPR. Yet here we are.