> Yes, but that does not change the incorrectness of the statement: "There is nothing in the GDPR about cookies."
I disagree, but it's a matter of semantics. I think we can agree that the operational part of the GDPR, the part that has legal force, doesn't mention cookies. Or storing/accessing information on the the terminal equipment of a user if you want to use that definition.
>GDPR regulates collection and storage of personal data. Cookies are a means of collection and storage of such data. GDPR does not need to mention cookies specifically.
But cookies can contain data that are not personal data, and those cookies require consent under the ePrivacy Directive.
And absent the ePD cookies wouldn't need consent (unless that was the legal basis being relied upon under the GDPR).
>The ePrivacy Directive addresses cookies specifically in Article 5(3). This "cookie rule" was not in the original regulation. It was added in 2009. The sudden increase in cookie consent requests on websites recently, and the subject of this Usenix presentation abstract, are probably not a response to the ePrivacy Directive.
No argument from me that the ePD has been (and is constantly being) ignored. And yes, the reason for the sudden increase in consent banners is because of the GDPR, for two reasons:
1) The ePD (as amended) referenced the Data Protection Directive which was replaced by the GDPR, and hence the definition of consent changed. But that still doesn't make violation of the ePD a violation of the GDPR.
2) The GDPR was very well publicised. That meant that people who had no idea what the hell all of this meant, and they first saw the requirements of the ePD at the same time as the GDPR (even though they should have been well aware of it already).
>The ePrivacy Directive is soon going to be replaced with something more up-to-date, with broader scope.
For some value of "soon". They've been promising that for six(!) years now. Hopefully the next round of trialogue (on the 31st March) will get it across the line.