Purely from a Devils Advocate perspective those banners are legally required, so pro-actively blocking them seems like a bad idea.
Purely from a Devils Advocate perspective those banners are legally required, so pro-actively blocking them seems like a bad idea.
If the users do not want to accept the proposal, they aren't required to, and they aren't required to even view and consider the proposal - there is nothing illegal if the users preemptively block and ignore it.
I believe there must be a strong push back on those banners from browser vendors to force the EU to reconsider the current law and modify it. IMHO it would be much better if they'd revise the current law to require browser vendors to have a global cookie setting (accept functional, marketing, etc.) and then websites having to obey to a user's preference based on their browser setting.
But they want to shovel a ton of trackers and tracking ads and analytics and other garbage into every page load, so they need to obtain consent before those can be loaded and then they try to be clever (read: illegal) and trick you into giving them a blank check by making it harder to opt out and continue than to opt in to everything and give up.
There's also nothing in the law saying the cookie banner has to be a modal dialog. The same sites happily went for actual "banners" rather than popups when the first EU cookie law was passed and only required notice rather than consent. They only went for modal popups because this forces users to make a choice before they can access the content.
Ironically, if a data protection agency were particularly spicy that day, it could be argued that putting a site behind a modal consent popup rather than defaulting to opt-out and merely informing the user about other options violates the GDPR's requirement not to make the use of a website conditional to unrelated data processing because the popup is intended as a form of light coersion.
Sure, my pet peeve is not that THERE IS something in EU law that makes these banners so annoying. My issue is that THERE ISN'T anything in the EU law that specifically prescribes HOW it should be handled so that it's not such an absolute fecking annoyance. As I said, I think they should revise the law so that it specifically states that the cookie options must be a browser option and websites MUST respect that preference, and that the browser preference trumps anything else which a user might have consented elsewhere, rendering attempts to workaround it as useless.
[0] https://github.com/InteractiveAdvertisingBureau/GDPR-Transpa...
That's like bank-robbers demanding that the law against armed robbery needs to be modified.
I like the law. I don't like the bank-robbers throwing up banners in the hope that the blame will stick to GDPR.
- Receive users’ consent before you use any cookies except strictly necessary cookies.
- Provide accurate and specific information about the data each cookie tracks and its purpose in plain language before consent is received.
- Document and store consent received from users.
- Allow users to access your service even if they refuse to allow the use of certain cookies
- Make it as easy for users to withdraw their consent as it was for them to give their consent in the first place.
Site owners don't have to use obnoxious banners to comply with any of these obligations:
- User consent can be collected _when the cookie is used_ rather than preemptively.
- Information can be provided when consent is asked and/or at a specific URL linked from the footer.
- Documenting and storing is a no-brainer.
- Allowing users to access the service without certain cookies is also a no-brainer.
- Allowing the user to change their mind can also be a simple form at a specific URL linked from the footer.
So-called cookie banners exist because they are simpler and cheaper than designing online services properly.
FWIW, I don't remember ever explicitly setting a cookie or reading from it in the last 6-8 years or so and I don't think I am the only one. Third party integrations have been the only source of cookies in all the projects I have been involved with in that timespan: YouTube embeds and tracking, mostly.
When I was coding up my poetry website I decided I wanted to give users the chance to share the poem they were reading on Facebook or Twitter - both of which require their cookies on the user's browser to make the functionality work. But I didn't want to ruin the user experience of visiting the site (that comes later, when they're reading the poem) by shoving a consent banner onto the screen as soon as the site loaded. The solution I came up with was to redirect the users to the site's cookie consents page[1] only after they clicked on the FB/Twitter share buttons, and only load the relevant cookies onto their browsers after they explicitly agree to them.
[1] - https://rikverse2020.rikweb.org.uk/cookies - because cookie consent pages can be fun too!
Another way to look at it, if I disable JavaScript and therefore the pop-ups don't show is that illegal?
Not a European or a lawyer, but I think "legally required" might be a slight question mark.
I could be very wrong, but I think the issue is that the requirements of these laws are all vaguely worded, so companies started putting in place these giant consent forms on load purely to cover their ass legally.