I do think this is better for privacy than standard id-based approaches, but the law is very strict. More: https://www.jefftk.com/p/why-so-many-cookie-banners
(Not a lawyer)
I do think this is better for privacy than standard id-based approaches, but the law is very strict. More: https://www.jefftk.com/p/why-so-many-cookie-banners
(Not a lawyer)
https://eur-lex.europa.eu/legal-content/EN/ALL/?uri=CELEX:32...
The ePrivacy directive itself has in article 3.1:
This Directive shall apply to the processing of personal data [...]
which would mean it doesnt apply here, as there is no personal data.In practice, I assume this one is for the judges.
This isn't a criticism of the law, I'm just curious what options there could be, because I can't think of any.
Tell them you'd rather make the coffee ;-)
We had a bunch of meetings about this at what essentially amounted to a giant information superhighway billboard company. IIRC someone brought up using cache headers even back then, because it didn't require cookies or javascript, which we couldn't guarantee would be "up to date", this is back in "target IE6, still" days.
As one of my networking friends said, advertisers usually know everything about your metrics, even if you don't. You can't really fudge the numbers in your favor, so raw requests or QPS or whatever ancillary metric would be enough.
the method in the article is defeated by clearing your session when you're done browsing, or using incognito/private browsing tab, as that should mark all "cached" items for deletion.
The withcabin.com landing page claims you don't need consent banners to use it.
> when the cookie is used “for the sole purpose of carrying out the transmission of a communication over an electronic communications network” (“Exemption A“)
Since the timestamp is no longer used solely for this purpose, you need consent.